Splunk Enterprise Security

What is the actual use of Expected Views lookup ?

damode
Motivator

Splunk doc says, Expected Views list specifies Splunk Enterprise Security views that are monitored on a regular basis.  But what are these views monitored for ?

What do I need to actually use this for ? Whats the usecase behind it ?

Labels (1)
0 Karma
1 Solution

lkutch_splunk
Splunk Employee
Splunk Employee

It's for internal auditing. From the ES menu bar, if you go to Audit > View Audit... it shows the "views" (or pages in the ES app) where your admins/analysts/users are looking most often.

The Expected Views lookup is configurable, so you can add views to it if you would expect that they should be monitored daily, and then you can see if they are. You would go to Configure > Content > Content Management, then search for Expected Views, and then edit it from there. 

View solution in original post

0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

It's for internal auditing. From the ES menu bar, if you go to Audit > View Audit... it shows the "views" (or pages in the ES app) where your admins/analysts/users are looking most often.

The Expected Views lookup is configurable, so you can add views to it if you would expect that they should be monitored daily, and then you can see if they are. You would go to Configure > Content > Content Management, then search for Expected Views, and then edit it from there. 

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...