Splunk® User Behavior Analytics

Use Splunk User Behavior Analytics

Create a custom dashboard

In addition to the dashboards built in to Splunk UBA, you can create custom dashboards with panels specific to your data and network.

Follow these steps to create a custom dashboard:

  1. From the Splunk UBA navigation menu select Analytics > Custom Dashboards.
  2. Select New Dashboard to give a name to your custom dashboard. For example, Network DeviceThreats.
  3. Select New Widget to add a dashboard panel.
  4. Enter a Widget Name. For example, Threats Count.
  5. Select a Widget Measure. For example, Threats Count to see a count of threats.
  6. Select Next.
  7. Select a widget grouping. For example, Device Types.
  8. Select Next.
  9. Select appropriate filters. For example, select Threat Categories and External to see only external threats.
  10. Check to see how many threats match the filters you select to make sure your widget displays data.
  11. Select Next.
  12. Select a visualization.
    For example, select a Bar Chart because it shows a helpful breakdown of threats by device type. The types of charts available for you to select depends on the data type.
  13. Select OK to save your new panel.
    This screen image shows the custom dashboard that was created by the procedure. The dashboard is titled "Threats Count (5)" and the data is represented by two bars in a horizontal bar chart. The first bar on top is labeled "Unknown" and has a value of 5, and the second bar, located below the first bar, is labeled "Client" and has a value of 4.

Modify a dashboard widget

After you create a dashboard widget, you can modify it. Complete the following steps:

  1. Hover over the chart and gear (Image of the pie chart and gears icon) icon in the upper right corner of the panel.
  2. Click the pencil icon to Edit Widget.
  3. Navigate through the widget screen to make the desired changes.
  4. Click OK when you are done to save your changes.

Modify a custom dashboard

You can also modify dashboards. Complete the following steps:

  • Click New Dashboard to create a new custom dashboard.
  • Select Actions > Delete Dashboard to remove a custom dashboard.
  • Select Actions > Rename Dashboard to rename the dashboard.
Last modified on 06 December, 2023
Customize a table view in Splunk UBA   Investigate Splunk UBA entities using watchlists

This documentation applies to the following versions of Splunk® User Behavior Analytics: 5.1.0,, 5.2.0, 5.2.1, 5.3.0, 5.4.0, 5.4.1

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters