Splunk Enterprise Security

The meaning of security metrics in Glass Tables

hungheo
New Member

Hi everyone,

I am newbie in Splunk. Now I need do a network Diagram in Glass Tables but I don't know exactly the meaning of security metrics.
Example :
Access - Distinct Apps, Access - Distinct Destinations, Access - Distinct Source, Access - Distinct Users
DNS - Errors, DNS - Messages, DNS - Query Sources, DNS-Unique queries
Email - Cloud Activity
Licensing - Average Events Per Day
Modular Actions - Action Invocations, Modular Actions- Avarage Duration, Modular Actions- Distinct Search Name

Please explain for me or send for me link document about it.
Thank everyone very much

0 Karma

alonsocaio
Contributor

Hi,

I guess that the Security Metrics are KPIs based on accelerated datamodels searches. If you click and open those security metrics you will see search that generates the metric.

It would be interesting for you to understand first your data sources and what data is being used for each datamodel. I have listed below some fields and datamodels used by the Security Metrics you asked.

Access - Distinct Apps -> Uses app field from datamodel Authentication.Authentication
Access - Distinct Destinations -> Uses dest field from datamodel Authentication.Authentication
Access - Distinct Source -> Uses src field from datamodel Authentication.Authentication
Access - Distinct Users -> Uses user field from datamodel Authentication.Authentication
DNS - Errors -> Counts based on reply code field from datamodel Network_Resolution.DNS
DNS - Messages -> Counts based on datamodel Network_Resolution.DNS
DNS - Query Sources -> Uses src field from datamodel Network_Resolution.DNS
Email - Cloud Activity -> Counts based on datamodel Email.All_Email
Licensing - Average Events Per Day -> Uses the lookup licensing_epd and macro licensing_epd
Modular Actions - Action Invocations -> Counts based on datamodel Splunk_Audit.Modular_Actions
Modular Actions- Avarage Duration -> Uses the field duration from datamodel Splunk_Audit.Modular_Actions
Modular Actions- Distinct Search Name -> Uses the field search_name from datamodel Splunk_Audit.Modular_Actions

Also, here are some interesting links from docs:
Create Glass Table -> https://docs.splunk.com/Documentation/ES/5.3.0/User/CreateGlassTable
Create KPI -> https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Createkeyindicatorsearches

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...