Splunk Enterprise Security

The meaning of security metrics in Glass Tables

hungheo
New Member

Hi everyone,

I am newbie in Splunk. Now I need do a network Diagram in Glass Tables but I don't know exactly the meaning of security metrics.
Example :
Access - Distinct Apps, Access - Distinct Destinations, Access - Distinct Source, Access - Distinct Users
DNS - Errors, DNS - Messages, DNS - Query Sources, DNS-Unique queries
Email - Cloud Activity
Licensing - Average Events Per Day
Modular Actions - Action Invocations, Modular Actions- Avarage Duration, Modular Actions- Distinct Search Name

Please explain for me or send for me link document about it.
Thank everyone very much

0 Karma

alonsocaio
Contributor

Hi,

I guess that the Security Metrics are KPIs based on accelerated datamodels searches. If you click and open those security metrics you will see search that generates the metric.

It would be interesting for you to understand first your data sources and what data is being used for each datamodel. I have listed below some fields and datamodels used by the Security Metrics you asked.

Access - Distinct Apps -> Uses app field from datamodel Authentication.Authentication
Access - Distinct Destinations -> Uses dest field from datamodel Authentication.Authentication
Access - Distinct Source -> Uses src field from datamodel Authentication.Authentication
Access - Distinct Users -> Uses user field from datamodel Authentication.Authentication
DNS - Errors -> Counts based on reply code field from datamodel Network_Resolution.DNS
DNS - Messages -> Counts based on datamodel Network_Resolution.DNS
DNS - Query Sources -> Uses src field from datamodel Network_Resolution.DNS
Email - Cloud Activity -> Counts based on datamodel Email.All_Email
Licensing - Average Events Per Day -> Uses the lookup licensing_epd and macro licensing_epd
Modular Actions - Action Invocations -> Counts based on datamodel Splunk_Audit.Modular_Actions
Modular Actions- Avarage Duration -> Uses the field duration from datamodel Splunk_Audit.Modular_Actions
Modular Actions- Distinct Search Name -> Uses the field search_name from datamodel Splunk_Audit.Modular_Actions

Also, here are some interesting links from docs:
Create Glass Table -> https://docs.splunk.com/Documentation/ES/5.3.0/User/CreateGlassTable
Create KPI -> https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Createkeyindicatorsearches

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...