Getting Data In

Splunk Assistance: How to create dashboards in Splunk?

SplunkDummy33
New Member

I am a student at Embry-Riddle Aeronautical University and i am attending MISA 532 Intgd Threat Warning Attk EIS. Our semester project is to create a dashboard using Splunk and adding panels each week. I am requesting assistance because i have been able to download Splunk successfully but have not been able to use Splunk to create dashboards. I am asking if someone can assist me in dashboard creations to be able to fulfill my class requirements. 

I am tasked to create three panels;

  • Access Denied/Privilege Escalation. how many failed attempts or PE were recorded.
  • Failed Log in. How many failed login attempts were detected by company users.
  • Social Media (OSINT). A dashboard showing OSINT information for employees. 
Labels (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SplunkDummy33,

your question is just a little vague, because, before arriving to create a dashboard, you should have ingested the data in your Splunk and have the knowledge to create the search that's the base for each dashboard, then you should know the matter of your dashboard (in your case MISA 532 Intgd Threat Warning Attk EIS) that means to know the fields and values that you can find in your data.

In other words: dashboards is the last step in your activity!

About data ingestion, see some video about getting data in: https://www.google.com/search?q=splunk+getting+data+in&rlz=1C1VDKB_itIT1048IT1048&oq=splunk+getting+...

About search creation, see the Splunk Search Tutotial: https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchTutorial/WelcometotheSearchTutorial

At least, about  dashboard (using Dashboard Studio), you can see at: https://www.google.com/search?q=splunk+dashboard+studio&sca_esv=559635945&rlz=1C1VDKB_itIT1048IT1048...

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...