Splunk Enterprise Security

Splunk Enterprise Security: How can I get Incident Review to refresh itself automatically?

LukeMurphey
Champion

I have Splunk Enterprise Security and I want Incident Review to refresh itself automatically. What is the best way to do this?

1 Solution

LukeMurphey
Champion

You can have Incident Review automatically update by running a real-time search. This will show updates automatically in real-time.

But I only want Incident Review to show notable events created from now on
Run an all-time real-time search if you want Incident Review to show all notable events that are created after the start the search. This works because an all-time real-time search doesn't back-fill; it will only show things coming in from now on.

But I want to show this on a big screen along with other dashboards
In this case, you may to consider using the Slideshow app. That app allows you to create shows consisting of a series of dashboards. It also supports a "dark-mode" that loos nice on a big-screen. Another option is using a browser plugin to cycle through dashboards.

View solution in original post

LukeMurphey
Champion

You can have Incident Review automatically update by running a real-time search. This will show updates automatically in real-time.

But I only want Incident Review to show notable events created from now on
Run an all-time real-time search if you want Incident Review to show all notable events that are created after the start the search. This works because an all-time real-time search doesn't back-fill; it will only show things coming in from now on.

But I want to show this on a big screen along with other dashboards
In this case, you may to consider using the Slideshow app. That app allows you to create shows consisting of a series of dashboards. It also supports a "dark-mode" that loos nice on a big-screen. Another option is using a browser plugin to cycle through dashboards.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...