Splunk® App for Splunk Attack Analyzer

User Guide

Usage Overview dashboard

The Usage Overview dashboard shows data about submissions to Splunk Attack Analyzer. You can filter this dashboard by time range, submission source, verdict, job ID, and the user who submitted information to Splunk Attack Analyzer.

Dashboard panels

Panel Description
Total Submissions (Selected Time) Displays the number of submissions to Splunk Attack Analyzer for your selected time range.
Submission by Source Displays a radial chart that shows how many submissions came through the Splunk Attack Analyzer user interface versus the API.
Submission by Verdict Displays a radial chart that shows the number of submissions by verdict such as phishing or malware.
Submissions Today vs Yesterday Displays the number of submissions to Splunk Attack Analyzer today and the difference from yesterday.
Submissions by Type Displays a radial chart that shows the number of submissions by type such as a URL, file, or email.
Submissions with Display Score Over 70 Displays a radial chart that shows the number of submissions with a score over 70.
Phish and Malware Observations Displays the count of phish brands, phish kits, and malware observed during your selected time frame. The drilldown for this panel opens the Credential Phishing and Malware dashboard.
All Submissions Over Selected Time Displays a bar chart showing the number of submissions to Splunk Attack Analyzer over your selected time range.
API Submissions Over Selected Time Displays a bar chart showing the number of API submissions to Splunk Attack Analyzer per day over your selected time range.
UI Submissions Over Selected Time Displays a bar chart showing the number of UI submissions to Splunk Attack Analyzer per day over your selected time range. You can also hover over a username to filter based on the number of submissions by that particular user in your selected time range.
Recent Submissions Displays a chart that provides information on recent submissions to Splunk Attack Analyzer. Select an entry on the table to open the drilldown for this chart which is the jobs page in Splunk Attack Analyzer for the entry you selected.
Last modified on 22 January, 2024
Dashboards included with the Splunk App for Splunk Attack Analyzer   Observations dashboards

This documentation applies to the following versions of Splunk® App for Splunk Attack Analyzer: 1.1.0, 1.1.1


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters