key indicator searches

key indicator searches


Searches in Splunk Enterprise Security that create a key indicator, which you can add to a dashboard as a security metric. Key indicator searches run against the data models defined in Splunk Enterprise Security or the data models defined in the Common Information Model app. Some key indicator searches run against the count of notable events.

For more information

In Administer Splunk Enterprise Security:
