Create and manage views in Splunk Enterprise Security
Create a new view or dashboard using Simple XML from Content Management.
Prerequisite
Creating new views and dashboards from Content Management requires familiarity with Simple XML. For an overview of building and editing dashboards, including working with Simple XML, see the Splunk platform documentation.
- For Splunk Enterprise, see Dashboard overview in Splunk Enterprise Dashboards and Visualizations.
- For Splunk Enterprise, see Dashboard overview in Splunk Enterprise Dashboards and Visualizations.
Task
- From the Enterprise Security menu bar, select Configure > Content > Content Management.
- Click Create New Content and select View.
- Create a new dashboard with Simple XML.
- Modify the permissions to share the new view with Enterprise Security so that you can view and manage it in Enterprise Security.
- From the Splunk bar, select Settings > User interface > Views.
- Locate the View name that you created.
- Click Permissions and modify the permissions to share the view with Enterprise Security.
- Click Save.
You can also create a new dashboard with the interactive dashboard editor. Select Search > Dashboards to open the Dashboards page. You can find information about the Dashboard Editor in the Splunk platform documentation.
- For Splunk Enterprise, see Open the Dashboard Editor in Splunk Enterprise Dashboards and Visualizations.
- For Splunk Cloud Platform, see Open the Dashboard Editor in Splunk Cloud Platform Dashboards and Visualizations.
Use the Navigation editor to change which dashboards are visible on the menu in your deployment. For more information, see Customize the menu bar in Splunk Enterprise Security.
Create and manage search-driven lookups in Splunk Enterprise Security | Export content from Splunk Enterprise Security as an app |
This documentation applies to the following versions of Splunk® Enterprise Security: 7.0.0
Feedback submitted, thanks!