[this is for v4.0.x of the Recorded Future App for Splunk Enterprise]
Install and Configure Reports
The easiest way to adapt or add new reports is to go to Other -> Reports.
Then click on 'Open in Search' on the report you want to adapt.
This will send you to a search page with the current reports search populated.
Here you can add or remove parts of the search. For example we might want to have a report that only looks at logs with the log level 'ERROR' instead of all logs. One way to do this is to click on the field 'loglevel' on the left column and, if 'ERROR' is available as a value click that, otherwise click on INFO and the search row will automatically add a 'loglevel=INFO'.
Just change 'INFO' to 'ERROR' and click search to view the result that would create the report.
Depending on if there has been any error logs thus far, the result might be empty, but it will still find any future error logs.
When you are happy with the search, click on the 'Save As' menu in the upper right corcer, and then click on 'Report' to save the new search as a new report. Fill out the information and click on save and you're done.
Your Recorded Future Intelligence Services consultant would be happy to help you with additional questions and advice. If you do not know who that is, you can also contact [email protected]
Please do not contact Splunk support about "Recorded Future for Splunk Enterprise".