Creating Dashboards for Nightfall Alerts in Splunk
Learn how to start creating a dashboard of Nightfall alerts/actions in your Splunk Enterprise/Splunk Cloud environment.
Integrating with SIEM
This snippet is from a Remediation event in Slack




This chart will show the different top Detectors that are triggered in the Violations 
This highlights our 'Credentials and Secrets' Detection Rule and gives us some key metrics, such as number of violations as well as overall percentage compared to other Rules

This above view breaks down the violation by the following: by Policy, by Detection Rule, by Channel 
Here, we can visualize the total number of Alerts and Actions that are occurring over 3 different integrations: Slack, Google Drive, and Github 
In this view, we can break down the Remediation actions that have taken place, broken down by the specific action. Also, we can tally our most consistent Nightfall violators.

Setting up a Dashboard for your Nightfall Alerts:
Step 1: Create a new Dashboard:
Step 2: Creating a Pivot Chart:





Step 3: Adding Multiple Charts and Viewing the Dashboard:



PreviousIntegrating with Microsoft SentinelNextCreating Dashboards for Nightfall Alerts in Sumo Logic
Last updated
Was this helpful?