Splunk Enterprise Security

What is the actual use of Expected Views lookup ?

damode
Motivator

Splunk doc says, Expected Views list specifies Splunk Enterprise Security views that are monitored on a regular basis.  But what are these views monitored for ?

What do I need to actually use this for ? Whats the usecase behind it ?

Labels (1)
0 Karma
1 Solution

lkutch_splunk
Splunk Employee
Splunk Employee

It's for internal auditing. From the ES menu bar, if you go to Audit > View Audit... it shows the "views" (or pages in the ES app) where your admins/analysts/users are looking most often.

The Expected Views lookup is configurable, so you can add views to it if you would expect that they should be monitored daily, and then you can see if they are. You would go to Configure > Content > Content Management, then search for Expected Views, and then edit it from there. 

View solution in original post

0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

It's for internal auditing. From the ES menu bar, if you go to Audit > View Audit... it shows the "views" (or pages in the ES app) where your admins/analysts/users are looking most often.

The Expected Views lookup is configurable, so you can add views to it if you would expect that they should be monitored daily, and then you can see if they are. You would go to Configure > Content > Content Management, then search for Expected Views, and then edit it from there. 

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...