Automatically Generate Dashboards

Table of Contents


This guide will show you how to ask Splunk Security to look at what data you have in your environment, and then create a set of dashboards that look at your live data, all following Splunk’s best practices for dashboard creation.


Security Posture Dashboards

Once you complete the Data Source Check, you can click “Create Posture Dashboards” in the upper right corner. That will let you create up to 50 dashboard panels looking at your actual data, and following Splunk best practices!

  1. The Security Posture dashboards only run on the data you have in your system, so make sure you run the Data Source Check searches first (or if you’ve run them before, click Retrieve Last Result.

  2. Once the checks are in place, you can click Create Posture Dashboards.

  3. There are three dashboards you can choose. Within each, some panels are enabled by default, some disabled, and some unavailable as you don’t have the required data.

  4. If you want to see the intended result, you can click Use Demo Datasets and all the dashboards will use CSV demo data.

  5. After clicking Create Dashboards, you will get a link to each dashboard. They’ll also be added to navigation.

  6. These are SimpleXML dashboards using Splunk best practices (with post-processing and using accelerated data models if possible). That makes them easy to customize, or copy-paste into your dashboards.