Create a glass table
Create a glass table to visualize and monitor the security status of your environment. You can add security metrics like key indicators or ad-hoc searches that update in real-time against a background that you design.
- In the Splunk Enterprise Security main menu, click Glass Tables.
- Click Create New Glass Table.
- Type a Title, Description, and set Permissions for your new glass table.
- Click Create Glass Table to create the glass table.
See Monitor threat activity in your environment with a glass table for a walkthrough of how to set up a glass table in the context of a security use case.
Build a glass table visualization
Create a glass table using the flexible canvas and editing tools on the glass table editor.
- From the list of Glass Tables, click the name of the glass table.
- Use the editing tools to upload images, draw shapes, add icons, add text, and make connections to reflect the relationship between the metrics.
- In the panel of security metrics, click any metric to view the key indicator search widgets available to add.
- Click and drag one or more of the key indicator search widgets onto the drawing canvas.
A widget appears on the canvas, displaying the associated search values, which continuously update in real-time.
- Add additional widgets to build out the dynamic elements of your visualization.
- Click Save.
Key indicator search values update at regular intervals according to the search schedule that you define when you create the search.
After you add a widget to your glass table, configure it to optimize performance, add a custom drilldown, and customize the widget appearance for a particular glass table design. Key indicator searches populate the widgets included in the glass table. Make changes to the key indicator searches on the Content Management dashboard.
- In the Glass Table editor, click a widget.
- For Custom Drilldown, click On.
- Select a drilldown destination or type a URL.
- For Viz Type, select an appropriate option to display your search results. Visualization types include single-value, gauge, sparkline, and single value delta.
- Click Update to update the widget configuration.
- Click Save.
Create and configure search widgets
You can also create a custom widget to display search results. Add a new search to any glass table, define a custom search string, and customize the appearance of the search widget using a variety of visualization types.
Write your custom search outside of glass table to confirm that it produces expected results. Your custom search must include the
timechart command, or
stats by _time to use thresholding.
- In the glass table editor, click and drag Ad hoc Search onto the canvas.
- In the Configurations panel, for Search Type, type your custom search string.
- Use the time picker to select the end time for your search. Defaults to Now.
- For Threshold Field, type the field that you want to use as the threshold for your search.
For example, count.
- For Thresholds, click On to enable the thresholds for the search widget.
- Click Edit to edit the threshold.
- In the threshold window, add thresholds for the search widget. This determines the color of the widget, which indicates the current status of the metric.
- Select a Viz Type for your search widget.
- Click Update to update the widget to the new visualization and display your search results over the specified time range.
- Click Save.
Creating new content in Splunk Enterprise Security
Managing glass tables
This documentation applies to the following versions of Splunk® Enterprise Security: 4.5.0, 4.5.1, 4.5.2, 4.5.3