Dashboards & Visualizations

How to create a dashboard that shows the total number of emails stopped by reputation filter Ironport?

Ghanayem1974
Path Finder

I want to create a dashboard that shows the total number of emails stopped by IronPort, along with Invalid recipients, spam but I am not sure what search I should start with.

0 Karma
1 Solution

adonio
Ultra Champion

hello there
onboard the ironport logs
leverage pre-built splunk apps for cisco: (i think this is the proper one)
https://splunkbase.splunk.com/app/1761/#/overview
read about the app here:
http://docs.splunk.com/Documentation/AddOns/latest/CiscoESA/About
search the data and the interesting fields and build your queries for panels in dashboard
or download the cisco security suite https://splunkbase.splunk.com/app/525/
which has some pre-built dashboards around your use case

example:

alt text

hope it helps

View solution in original post

0 Karma

adonio
Ultra Champion

hello there
onboard the ironport logs
leverage pre-built splunk apps for cisco: (i think this is the proper one)
https://splunkbase.splunk.com/app/1761/#/overview
read about the app here:
http://docs.splunk.com/Documentation/AddOns/latest/CiscoESA/About
search the data and the interesting fields and build your queries for panels in dashboard
or download the cisco security suite https://splunkbase.splunk.com/app/525/
which has some pre-built dashboards around your use case

example:

alt text

hope it helps

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...