A community-built SPL + dashboard repository
GoSplunk
Discover field-tested SPL searches and full dashboard XML you can copy straight into Splunk.
Sample SPL
index=security EventCode=4625
| stats count by Account_Name, ComputerName
| sort - count 128
SPL searches
Hand-picked SPL searches from across the library.
Investigate by MAC, IP all VPN authentications through CISCO_ISE
Hard Disk Usage and Information on Splunk Server
Bucket Count by State over Index
Real Time IIS Web Site Connections
Searches to check search concurrency for historical or real time
Number of Accounts Created in a Windows Environment
Linux Deletion of SSL Certificate (mitre : T1485 , T1070.004 , T1070)
User Agent - Browser Details & Information for IIS
Last Time a Forwarder Checked In
Dashboards
Full XML dashboards with panels, inputs, and drilldowns. Copy once, ship instantly.