Splunk Enterprise

Query

NOORULAINE
Loves-to-Learn Lots

Hi
i am trying to build a dashboard and I require a query to execute below some searches below: 

1. REPORT FALSE POSITIVE PER TOTAL

 2. REPORT MONTHLY SPLUNK ALERT HIGH - MEDIUM - LOW

Can anyone help me in building the same?

Labels (1)
Tags (2)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Start with a search to return the events you are interested in. Since you didn't provide any details of what events you have, nor what you want in your dashboard, I am not sure how much more help can be given.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...