Splunk Enterprise Security

What is the actual use of Expected Views lookup ?

damode
Motivator

Splunk doc says, Expected Views list specifies Splunk Enterprise Security views that are monitored on a regular basis.  But what are these views monitored for ?

What do I need to actually use this for ? Whats the usecase behind it ?

Labels (1)
0 Karma
1 Solution

lkutch_splunk
Splunk Employee
Splunk Employee

It's for internal auditing. From the ES menu bar, if you go to Audit > View Audit... it shows the "views" (or pages in the ES app) where your admins/analysts/users are looking most often.

The Expected Views lookup is configurable, so you can add views to it if you would expect that they should be monitored daily, and then you can see if they are. You would go to Configure > Content > Content Management, then search for Expected Views, and then edit it from there. 

View solution in original post

0 Karma

lkutch_splunk
Splunk Employee
Splunk Employee

It's for internal auditing. From the ES menu bar, if you go to Audit > View Audit... it shows the "views" (or pages in the ES app) where your admins/analysts/users are looking most often.

The Expected Views lookup is configurable, so you can add views to it if you would expect that they should be monitored daily, and then you can see if they are. You would go to Configure > Content > Content Management, then search for Expected Views, and then edit it from there. 

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...