Table of Contents
2 Introduction to Splunk Reports and Dashboards 2
2.1 Learning About Transforming Commands 2
2.2 Using Transforming Commands 3
2.5 Creating Reports in Splunk 6
3 Building Splunk Dashboards 6
3.1 Building Splunk Dashboards 6
3.2 Customizing Splunk Dashboards 8
3.3 Creating Dashboards with Visualizations and Drilldowns 11
3.4 Adding Additional Configurations 13
3.5 Optimizing Splunk Dashboards 15
3.5.1 Reporting Acceleration 16
3.6 Configuring Additional Options 18
3.7 Managing Splunk Dashboards 18
4 Creating Alerts in Splunk 20
4.1 Creating Alerts in Splunk 20
4.2 Creating Scheduled Reports and Alerts 22
4.3 Detailing Advanced Alert Actions 24
4.4 Configuring Advanced Alert Actions 27
4.5 Wrapping up Splunk Reports, Dashboards, and Alerts 27
Course Overview
Joe Abraham, www.defendthenet.com
Introduction to Splunk Reports and Dashboards
Learning About Transforming Commands
Using Transforming Commands
Reporting in Splunk
index=main EventCode!=0
| table Eventcode,ComputerName
index=main EventCode!=0 | table Eventcode > eventcode not displaying ???
Creating Reports
Timepicker is default in reports – we can remove
Creating Reports in Splunk
Building Splunk Dashboards
Building Splunk Dashboards
Customizing Splunk Dashboards
Creating Dashboards with Visualizations and Drilldowns
Login – Search & Reports – Dashboards
Create New Dashboards
Classic Dashboard
Add Panel
Adding Additional Configurations
Add Input
We can look / import / modify the source code by clicking Source
UI = User Interface
Source = source code
Add Panel
Add Input
Edit drilldown – it goes to another search page with the clicked value
Token
Optimizing Splunk Dashboards
Reporting Acceleration
Settings – Searchs, reports and alerts – Edit for the report – Edit Acceleration
Accelerated report the symbol shows
We can edit the dashboard by clicking Dashboards – Edit
We can clone the Classic Dashboard to Dashboard studio
Cloned one is
Configuring Additional Options
If we clone to dashboard studio, datasource names are not cloned it says unnamed
Dashboard Studio
Dashboard is good which has more options
Managing Splunk Dashboards
Creating Alerts in Splunk
Creating Alerts in Splunk
Creating Scheduled Reports and Alerts
??? index – here we send to existing index – know more
Detailing Advanced Alert Actions
Webhook –
Logging and Indexing
Configuring Advanced Alert Actions
Alert to lookup table
Wrapping up Splunk Reports, Dashboards, and Alerts
No comments:
Post a Comment