Splunk dashboard that displays User searches

Built this dashboard to give a high level overview of user search activity.  The search powering the dashboard is looking that the _audit index and you will need to ensure that you have proper access to the internal Splunk indexes.

The dashboard includes a TimeRange picker, radio button to include or exclude Splunk’s system user, a dynamic multiselect input for users you wish to see and a text input that will add the value typed into the search (ex: type the word opnsense to see any search that had that term included).

Hope you enjoy and find this dashboard useful.

Updated on 4/7/2022 with suggestions from a fellow co-worker (thanks josh.a) to include a few more columns and have the “Filter” box only filter on values in the “search” field.   Also renamed the Filter to Search Filter.

 

Share This:

Leave A Comment?