Splunk® Security Essentials

Use Splunk Security Essentials

This documentation does not apply to the most recent version of Splunk® Security Essentials. For documentation on the most recent version, go to the latest release.

Track your content with the Manage Bookmarks dashboard

The Manage Bookmarks dashboard helps you track content in your environment, including content you've bookmarked or content that you've marked as successfully implemented. After you've bookmarked content, track the status of your bookmarked content by following these steps:

  1. In Splunk Security Essentials, navigate to Security Content > Manage Bookmarks.
  2. Set the status of your bookmarked content in the content table to Bookmarked, Waiting on Data, Ready for Deployment, Deployment Issues, Needs Tuning, Successfully Implemented, or Custom.
  3. (Optional) Define a custom bookmark status through the Lookup File Editor app by using the lookup / bookmark_names and adding a name and description. You can modify any of the statuses other than Bookmarked or Successfully Implemented. To download the Lookup File Editor app, see https://splunkbase.splunk.com/app/1724/ . The referencekey field in the bookmark_names lookup is optional for any of the statuses.
  4. (Optional) Add notes to describe the status of the content.
  5. (Optional) Remove the content once you're done using it.
  6. (Optional) Click Export to export the content. Export options include XLSX, CSV, Doc, Snapshot JSON, and Print-to-PDF.

You can also use Content Introspection from this page. For more information on Content Introspection, see Track active content in Splunk Security Essentials using Content Introspection.

Last modified on 06 January, 2021
See visualizations in the Overview dashboard   Customize Splunk Security Essentials with the Custom Content dashboard

This documentation applies to the following versions of Splunk® Security Essentials: 3.3.0, 3.3.1, 3.3.2, 3.3.3, 3.3.4, 3.4.0, 3.5.0, 3.5.1, 3.6.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters