soc30 / lms
connected
splunk>enterprise
Administrator ▾Settings ▾
ES
Enterprise Security
Splunk App for Enterprise Security · v7.3.0
DAY 17 LAB · LAB 17 — TOUR SPLUNK ES· week 3
Tour every Splunk ES dashboard, menu, and concept.
  • Click every top-level tab.
  • Open every Security Domain (Access, Endpoint, Network, Identity).
  • Find Risk Analysis, Threat Activity, Asset Investigator.
Hint: ES is built on Splunk Core — every panel runs SPL underneath.

Security Posture

Key Security Indicators · click a tile to drill into Incident Review
Notable Events By Urgency
critical3
high4
medium2
low1
informational0
Notable Events Over Time
Top Notable Events
rule_namecount
Brute Force - Failed Logins1
Suspicious PowerShell EncodedCommand1
Threat Match - Network1
Lateral Movement - PsExec1
Mass File Encryption1
Phishing URL Clicked1
Top Sources
srccount
10.4.12.503
10.4.12.913
203.0.113.421
10.2.7.1101
Toronto/Berlin1