Install and Configure: Reports

[this is for v4.0.x of the Recorded Future App for Splunk Enterprise]

Install and Configure Reports

The easiest way to adapt or add new reports is to go to Other -> Reports.

Other -> Reports

Then click on 'Open in Search' on the report you want to adapt.

Open in Search

This will send you to a search page with the current reports search populated.

Search bar

Here you can add or remove parts of the search. For example we might want to have a report that only looks at logs with the log level 'ERROR' instead of all logs. One way to do this is to click on the field 'loglevel' on the left column and, if 'ERROR' is available as a value click that, otherwise click on INFO and the search row will automatically add a 'loglevel=INFO'.

Field values

Added to search bar

Just change 'INFO' to 'ERROR' and click search to view the result that would create the report.

Change to ERROR

Depending on if there has been any error logs thus far, the result might be empty, but it will still find any future error logs.

When you are happy with the search, click on the 'Save As' menu in the upper right corcer, and then click on 'Report' to save the new search as a new report. Fill out the information and click on save and you're done.

Save dialogue

Further help

Your Recorded Future Intelligence Services consultant would be happy to help you with additional questions and advice.  If you do not know who that is, you can also contact [email protected]

Please do not contact Splunk support about "Recorded Future for Splunk Enterprise".

 

Was this article helpful?
0 out of 0 found this helpful

The content of this article is confidential and intended solely for the use of individuals with authorized access to the Recorded Future service. Do not download or distribute this article.
Have more questions? Submit a request

Comments

0 comments

Please sign in to leave a comment. Please note that your name will be displayed. If you would like to change how your name appears, please update your profile name.