Gain insights with the Threat intelligence dashboard
overview of the Threat Intelligence dashboard
The Threat intelligence dashboard displays the aggregated threat intelligence data that your system has ingested, providing insights for enrichment and detection matching.
To reach the Threat intelligence dashboard, located within Splunk Enterprise Security, select Analytics, then Threat intelligence.
Use the filters along the top of the dashboard to control the information displayed on the dashboard. If you do not make a selection, the dashboard defaults to using all data for the last 90 days.
You can also select the filter icon in any of the dashboard panels to filter data displayed on the entire dashboard.
-
Time: Select the time period for data you want to display.
Note: The dashboard displays data only for activated data sources, sources that you have activated to ingest data during some or all of the time range specified. -
Source: Select one or more threat data sources. For details on sources, see Configure threat intelligence sources in Splunk Enterprise Security.
-
Threat actor: Select one or more attributed threat actors.
-
MITRE ATT&CK tactic:Select one or more MITRE ATT&CK tactics. For additional information about MITRE ATT&CK tactics, see attack.mitre.org.
-
Malware: Select one or more malware types.
-
Observable by type: Select one or more types of observable found in your system, like domain name, email address, or IP addresses.
A warning icon on any filter field or dashboard panel indicates that there is no available data for your selections.
Panels of the dashboard
The Threat intelligence dashboard includes the following panels. Hover over graphical panels to see specific data in each group or date.
-
Daily observable count: A time chart showing unique observables per day. Days without observables are shown as zeroes. Upward or downward trend shown
-
Observable by type: Unique observable count, grouped by category
-
Number of daily indicator submissions: Daily submissions, separated by TIM (Cloud) and ES Native.
-
Indicator age distribution: Breakdown of indicator age by groupings of 0-24 hours, 1-7 days, 7-30 days, and over 30 days.
-
Source summary: Displays the filtered data sources activated during the some or all of the time range selected. Includes the following sortable data columns:
-
Unique observables: Count of unique suspicious observables, like IPs, domains, hashes, and users. Indicates the coverage, or breadth of observables, from the source. A higher count here means more distinct suspicious observables that your detections might potentially match against.
-
Unique indicator submissions: Count of unique submitted records over time, indicating the reporting activity of the source, including volume, churn, and repeat reporting. A higher count here might mean that there are duplicate observables reported, updated or resubmitted. It might also indicate that the source is actively refreshing intelligence, adding context, or corroborating the same threat.
-
Matching indicators: Count of how many indicators from this source match threat activity in your environment. If a source has few observables, but many matches, it might be highly valuable operationally. If a source has lots of unique observables, but very few matching indicators, it might have broad coverage, but not be very relevant to your environment.
Review the various combinations of the Unique observables and Unique indicator submissions values to help assess your sources:
Unique observables count Unique indicator submissions count Interpretation High High Broad and active source High Low Compact feed with broad, distinct coverage Low High Lots of repeated or updated reporting around the same observables Low Low Smaller or quieter source -
-
Threat actors: Threat actors for the given filters, initially sorted by indicator count.
-
MITRE ATT&CK tactics: MITRE ATT&CK tactics for the given filters, initially sorted by indicator count.
-
Malware: Malware types for the given filters, initially sorted by indicator count.
Select the magnifying glass icon in any panel to open the SPL search page that relates to the data that panel. Any edits you make to the SPL do not reflect back in the dashboard.