Splunk Enterprise Security

The meaning of security metrics in Glass Tables

hungheo
New Member

Hi everyone,

I am newbie in Splunk. Now I need do a network Diagram in Glass Tables but I don't know exactly the meaning of security metrics.
Example :
Access - Distinct Apps, Access - Distinct Destinations, Access - Distinct Source, Access - Distinct Users
DNS - Errors, DNS - Messages, DNS - Query Sources, DNS-Unique queries
Email - Cloud Activity
Licensing - Average Events Per Day
Modular Actions - Action Invocations, Modular Actions- Avarage Duration, Modular Actions- Distinct Search Name

Please explain for me or send for me link document about it.
Thank everyone very much

0 Karma

alonsocaio
Contributor

Hi,

I guess that the Security Metrics are KPIs based on accelerated datamodels searches. If you click and open those security metrics you will see search that generates the metric.

It would be interesting for you to understand first your data sources and what data is being used for each datamodel. I have listed below some fields and datamodels used by the Security Metrics you asked.

Access - Distinct Apps -> Uses app field from datamodel Authentication.Authentication
Access - Distinct Destinations -> Uses dest field from datamodel Authentication.Authentication
Access - Distinct Source -> Uses src field from datamodel Authentication.Authentication
Access - Distinct Users -> Uses user field from datamodel Authentication.Authentication
DNS - Errors -> Counts based on reply code field from datamodel Network_Resolution.DNS
DNS - Messages -> Counts based on datamodel Network_Resolution.DNS
DNS - Query Sources -> Uses src field from datamodel Network_Resolution.DNS
Email - Cloud Activity -> Counts based on datamodel Email.All_Email
Licensing - Average Events Per Day -> Uses the lookup licensing_epd and macro licensing_epd
Modular Actions - Action Invocations -> Counts based on datamodel Splunk_Audit.Modular_Actions
Modular Actions- Avarage Duration -> Uses the field duration from datamodel Splunk_Audit.Modular_Actions
Modular Actions- Distinct Search Name -> Uses the field search_name from datamodel Splunk_Audit.Modular_Actions

Also, here are some interesting links from docs:
Create Glass Table -> https://docs.splunk.com/Documentation/ES/5.3.0/User/CreateGlassTable
Create KPI -> https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Createkeyindicatorsearches

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...