SOC operations dashboard
The SOC Operations dashboard is designed to provide insight into the security operations center (SOC) based on key metrics, workflows, and dispositions so that you can monitor the efficiency of the SOC and ensure that all security operations (detections, analysis, and responses) are on track.
Dashboard panels
Key metrics
Panel | Description and default search |
---|---|
Mean Time to Triage | Displays the average time (in minutes) to triage or prioritize the investigation of a notable over the duration of a specified time period. Also, displays a trendline (in absolute value) that indicates how the mean time taken to triage the notable compares to the previous mean time taken to triage the notable over the same time period. For example, the trendline may display that the mean time to triage a notable over the last 7 days is 0.5% up or down over the mean time taken to triage the notable during the previous 7 day time period. For more information, see Triage notable events in Splunk Enterprise Security.
|
Mean Time to Resolution | Displays the average time (in minutes) taken by the notable to reach its configured end status over the duration of a specified time period. Also, displays a trendline (in absolute value) that indicates how the mean time taken by the notable to reach its configured end status compares to the previous mean time taken by the notable to reach its configured end status over the same time period. For more information, see Take action on notable events in Splunk Enterprise Security.
|
Investigations Created | Displays the number of investigations created in the SOC over the duration of a specified time period. Also, displays a trendline (in absolute value) that indicates how the mean number of investigations created compares to the previous mean number of investigations created over the same time period. For more information, see Start an investigation in Splunk Enterprise Security.
|
Workflow
Panel | Description and default search |
---|---|
Assigned Notables Over Time | Displays a comparison graph of assigned versus unassigned notables over the duration of a specified time period.
|
Notables in End State by Time | Displays a comparison graph for notables that are assigned versus the notables that have been resolved i.e. reached the configured end state over the duration of a specified time period.
|
Analyst Close Rate Over Time | Displays a comparison graph for assigned open versus assigned closed notables by an analyst over the duration of a specified time period.
|
Dispositions
Panel | Description and default search |
---|---|
Dispositions Over Time | Displays a distribution of the various dispositions that are assigned to notables over the duration of a specified time period. This visualization provides insight into the number of notables that are false positives versus notables that are true positives. For more information on assigning dispositions to notables, see Add dispositions to notables.
|
Sources Contributing to False Positive - Incorrect Analytic Logic | Displays a list of sources, which generated notables that have the disposition False Positive - Incorrect Analytic Logic over the duration of a specified time period.
|
Sources Contributing to False Positive - Inaccurate Data | Displays a list of sources, which generated notables that have the disposition False Positive - Inaccurate Data over the duration of a specified time period.
|
Sources Contributing to True Positive - Suspicious Activity | Displays a list of sources, which generated notables that have the disposition True Positive - Suspicious over the duration of a specified time period.
|
Sources Contributing to True Positive - Suspicious but Expected | Displays a list of sources, which generated notables that have the disposition True Positives - Suspicious, but Expected over the duration of a specified time period.
|