Splunk® Mission Control

Investigate and Respond to Threats in Splunk Mission Control

Monitor activities in Splunk Mission Control

You can monitor activities in Splunk Mission Control using the Mission Control Operation dashboard.

Review Splunk Mission Control activities

You can review Splunk Mission Control SOC operations, including incident response metrics and other statistics for incidents in your environment using the Mission Control Operation dashboard.

  1. Select Apps then Search & Reporting.
  2. Select Dashboards, then select Mission Control Operation from the list.
  3. Review the various metrics present.
  4. (Optional) Select the search icon to open a metric in search.
  5. (Optional) Export the entire dashboard by selecting Export, or hover over a certain metric and select the export icon to export only that specific metric.

If you have the sc_admin or admin role, you can also search audit logs and audit certain actions using the _audit index. See Search audit data in Splunk Mission Control.

Modify the Mission Control Operation dashboard

You can modify the layout and content of the Mission Control Operation dashboard.

  1. While viewing the dashboard, select Edit.
  2. Use the editing pane and the canvas to modify settings for each object on the dashboard.
    1. Select and drag visualizations and objects on the dashboard to modify the dashboard layout.
    2. Select Source to edit the JSON format.
  3. (Optional) Select + Add Panel or + Add Input to add additional metrics or input to the dashboard.
  4. Select Save.
Last modified on 02 June, 2023
Modify app level permissions for Splunk Mission Control   Splunk Mission Control scenario library

This documentation applies to the following versions of Splunk® Mission Control: Current

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters