Splunk® Enterprise Security

Use Splunk Enterprise Security

Download manual as PDF

This documentation does not apply to the most recent version of ES. Click here for the latest version.
Download topic as PDF

Entity Investigator dashboards

The Entity Investigator dashboards show types of notable events displayed by swim lanes over time, with heat maps to indicate the number for each type of notable event.

ES-Entity Investigator mockup.png

mockup of dashboard - screens to come later

  • swim lanes
  • time picker
  • heat map

Use the section below the main panel to select a type of notable event and zoom in on the details, changing the time span and granularity.

Asset Investigator

The Asset Investigator dashboard shows information about a particular asset in several different areas. The information panel describes the asset that is displayed.

ES-Asset Investigator.png

Need a new screenshot with better data

Click "Today" to select a different time span or drag the edges of the time bar to change the time range for the view.

The following table describes the swimlanes for this dashboard.

Swimlane Description
All Authentication
All Changes
Threat List Activity
IDS Attacks
Malware Attacks
Notable Events

Identity Investigator

The Identity Investigator dashboard shows information about a particular identity in several different areas. The information panel provides information about the identity that is displayed.

Es-identity investigator.png

Need a new screenshot with better data

Click "Today" to select a different time span or drag the edges of the time bar to change the time range for the view.

The following table describes the swimlanes for this dashboard.

Swimlane Description
All Authentication
All Changes
Threat List Activity
IDS Attacks
Malware Attacks
Notable Events

Edit the swim lanes

You can modify the swim lanes displayed in the Identity Investigator dashboard. Click Edit at the top of the dashboard. The swim lane editor can be used to change the group of swim lanes (default or custom), the order of the lanes, or the color used to represent events for that lane.

Es-identity investigator edit lanes.png

  • Choose default or custom collection of lanes
  • Choose order of lanes
  • Choose color to represent events for that lane
Last modified on 04 December, 2013
PREVIOUS
Predictive Analytics dashboard
  NEXT
Advanced Threat dashboards

This documentation applies to the following versions of Splunk® Enterprise Security: 3.0, 3.0.1


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters