soc30 / lms
connected
back to day 13
WEEK_2 · DAY_13 · LAB

Lab 13 — Build a SOC Dashboard

Build SOC dashboards with Studio, tokens, drilldowns, scheduled PDFs

LAB PROGRESS0/4 steps · 0%

Lab Objectives

  • Build a SOC dashboard from scratch in Dashboard Studio
  • Wire time pickers and dropdowns with tokens
  • Configure drilldowns for click-through investigation
  • Schedule reports as PDF for executives

Lab Instructions

  1. 1
    Open Splunk → Posture (or Search → New Dashboard).
  2. 2
    Build 4 panels: notable count by urgency, trend over 7d, top 10 sources, top 10 ATT&CK techniques.
  3. 3
    Add a time picker that updates all panels.
  4. 4
    Configure drilldown from any bar → Incident Review filtered.