Track data ingest latency with the Data Availability dashboard
The Data Availability dashboard is a machine learning-driven dashboard that tracks the typical data ingest latency of the products configured in Splunk Security Essentials. When a log source slows down, it is color coded in the dashboard, and you can click on it to see what detections are at risk.
Prerequisites
The Data Availability dashboard requires the Splunk Machine Learning Toolkit (MLTK). Verify that you have MLTK installed. See Install the Machine Learning Toolkit in the Splunk Machine Learning Toolkit User Guide.
Steps
- In Splunk Security Essentials, navigate to Data > Data Availability.
- Click Run Baseline Search.
- Click the log sources in the search results to see if there are any detections at risk for that specific source.
Track active content in Splunk Security Essentials using Content Introspection | Check data sources with the Data Source Check dashboard |
This documentation applies to the following versions of Splunk® Security Essentials: 3.3.0, 3.3.1, 3.3.2, 3.3.3, 3.3.4, 3.4.0, 3.5.0, 3.5.1, 3.6.0
Feedback submitted, thanks!