Splunk® Enterprise Security

Administer Splunk Enterprise Security

Customize table settings for the analyst queue in Splunk Enterprise Security

Customize table settings in the Analyst queue to display the fields for findings.

Follow these steps to display specific fields for a finding in the Analyst queue' table on the Mission Control page:

  1. In the Splunk Enterprise Security app, go to the Mission Control page.
  2. Select the gear icon to open the Table Settings dialog.
  3. Select the fields that you want to display in the Analyst queue table on the Mission Control page from the Available Columns. The fields you select get displayed in the Selected Columns.
  4. (optional)Reorder the selected fields in the Selected Columns based on the order in which you want them to display.
  5. Select Apply to apply your changes to the table.

The following screenshot shows how you can use the Table Settings to specify the fields that you want to display for a finding on the Mission Control page:

Screenshot displaying how to configure table settings for the Analyst queue

Last modified on 14 June, 2024
Manage saved views to display findings and investigations in Splunk Enterprise Security   Use detections to search for threats in Splunk Enterprise Security

This documentation applies to the following versions of Splunk® Enterprise Security: 8.0.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters