Splunk® Enterprise Security

Administer Splunk Enterprise Security

Create and manage views in Splunk Enterprise Security

Create a new view or dashboard using Simple XML from Content Management.

Prerequisite

Creating new views and dashboards from Content Management requires familiarity with Simple XML. For an overview of building and editing dashboards, including working with Simple XML, see the Splunk platform documentation.

  • For Splunk Enterprise, see Dashboard overview in Splunk Enterprise Dashboards and Visualizations.

Task

  1. From the Enterprise Security menu bar, select Security content then Content management.
  2. Select Create New Content and select View.
  3. Select a new dashboard with Simple XML.
  4. Modify the permissions to share the new view with Enterprise Security so that you can view and manage it in Enterprise Security.
    1. From the Splunk bar, select Settings > User interface > Views.
    2. Locate the View name that you created.
    3. Select Permissions and modify the permissions to share the view with Enterprise Security.
    4. Select Save.

You can also create a new dashboard with the interactive dashboard editor. Select Search > Dashboards to open the Dashboards page. You can find information about the Dashboard Editor in the Splunk platform documentation.

Use the Navigation editor to change which dashboards are visible on the menu in your deployment. For more information, see Customize the menu bar in Splunk Enterprise Security.

Last modified on 22 August, 2024
Create and manage search-driven lookups in Splunk Enterprise Security   Export content from Splunk Enterprise Security as an app

This documentation applies to the following versions of Splunk® Enterprise Security: 8.0.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters