Exposure Analytics diagnostics

The Exposure analytics diagnostics dashboards give administrators in Splunk Enterprise Security visibility into the configuration, health, and operational activity of the application. They consolidate audit reporting, inventory data exporting, and system health monitoring in one place, so administrators can verify that the app is configured correctly, track who has made changes, and diagnose performance or compliance issues before they affect analysis.

To view the dashboards, select Analytics, then Exposure analytics, then Exposure analytics diagnostics. Then select the tab for the information you want to view.

Operational health

The Operational health dashboard, the default dashboard, includes information on data source health, internal lookup health, processing search times, failed searches, skipped searches, KV store details, and more.

Check the health of your data sources in the Entity discovery sources table at the top of the Operational health page. If the last seen date for a data source exceeds the window shown, its health shows as Fail. If a source has been seen within the window, its health shows as Pass. The Health window is set for each source from the Entity discovery sources view. By default, the window for sources is set to 1 day.

You can use additional data on this dashboard to report on the health of Exposure Analytics. For example, you might find that the run time for a processing search is particularly high. A high run time typically indicates a high search load on the Splunk search head or that one or more entity discovery sources are misconfigured.

The following table defines the health statuses for processing search run times:

Health status Description
Good The run-time is under 3 minutes.
OK The run time is 3–4 minutes.
Elevated The run time is 4–5 minutes.
Critical

The run time is over 5 minutes.

Investigate your entity discovery sources to see if they require reconfiguration or adjustment.

Entity discovery sources

Select from different entities to identify the entity discovery sources that contribute to each field. You can choose to display by count or percentage. For example, the CMDB data source might contribute 200 entity records to the asset_class field. If the Total entities column count for that field is 800, then the percentage display for CMDB would be 25%. The Total entities row displays the unique entities discovered by each source, not a sum of entities from the rows below it. Many unique entities will be discovered by multiple sources.

Configuration audit

The Configuration audit dashboard reports on local configurations, which include the following:

  • Changes that might override the original configuration

  • Additions that are new and do not override the original configuration

The Result column shows how an item compares to the original configuration with a value of either  different or identical. To find a particular configuration change, filter by type, file, parameter, and more.

Configuration analyzer

Use the Configuration analyzer to check the health of inventory data stores and other configurations. You might use this view for troubleshooting or analysis when working with Splunk Support.

Operational logs

Search the Operational logs dashboard to view details of actions taken by users.

Data export

Keep copies of your inventory information by exporting your data in either CSV or JSON format.

To export your data, select the type of data you want to export, view the data, then select Download.

Data inventory choices include:

  • IP address inventory

  • MAC address inventory

  • Asset inventory

  • User inventory