Splunk® User Behavior Analytics

Use Splunk User Behavior Analytics

Acrobat logo Download manual as PDF

Acrobat logo Download topic as PDF

Create a custom dashboard

In addition to the dashboards built in to Splunk UBA, you can create custom dashboards with panels specific to your data and network.

  1. Select Analytics > Custom Dashboards.
  2. Click New Dashboard to add a name to your custom dashboard.
    For example, Network device threats.
  3. Click New Widget to add a dashboard panel.
  4. Enter a Widget Name.
    For example, Threats Count.
  5. Select a Widget Measure.
    For example, Threats Count to see a count of threats.
  6. Click Next.
  7. Select a widget grouping.
    For example, Device Types.
  8. Click Next.
  9. Select appropriate filters.
    For example, select Threat Categories and External to see only external threats.
  10. Check to see how many threats match the filters you select to make sure your widget displays data.
  11. Click Next.
  12. Select a visualization.
    For example, select a Bar Chart because it shows a helpful breakdown of threats by device type. The types of charts available for you to select depends on the data type.
  13. Click OK to save your new panel.
    This screen image shows the custom dashboard that was created by the procedure. The dashboard is titled "Threats Count (5)" and the data is represented by two bars in a horizontal bar chart. The first bar on top is labeled "Unkown" and has a value of 5, and the second bar, located below the first bar, is labeled "Client" and has a value of 4.

Modify a dashboard widget

After you create a dashboard widget, you can modify it.

  1. Hover over the chart and gear (Image of the pie chart and gears icon) icon in the upper right corner of the panel.
  2. Click the pencil icon to Edit Widget.
  3. Navigate through the widget screen to make the desired changes.
  4. Click OK when you are done to save your changes.

Modify a custom dashboard

You can also modify dashboards.

  • Click New Dashboard to create a new custom dashboard.
  • Select Actions > Delete Dashboard to remove a custom dashboard.
  • Select Actions > Rename Dashboard to rename the dashboard.
Last modified on 10 December, 2020
Customize your table view in Splunk UBA
Investigate Splunk UBA entities using watchlists

This documentation applies to the following versions of Splunk® User Behavior Analytics: 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4,, 5.0.5,, 5.1.0,, 5.2.0

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters