Use System Insights
view data in System Insights dashboards
View your automation data in dashboards.
To open the System Insights dashboard, follow these steps, depending on the app you are using:
-
Within Splunk Enterprise Security: Select Analytics, then Automation system insights.
-
Within Splunk App for SOAR: Select System Insights.
Tabs
There are several tabs that display your data. For each of these tabs, you can specify search terms, a time range, and your Splunk SOAR Host. The phantom_system_insights index contains the relevant information, however you can change the index if desired.
| View | Description |
|---|---|
| Overview | Default view. Provides a view into the overall health of your system. Sections include actions, playbooks, and assets by status; playbook and action runs over time, playbook runs pending, and a list of all playbook failures. |
| Actions | Sections include actions failed, actions by status, top failed actions, top actions ran, and a list of action run history. |
| Assets and ingestion | Provides an overview of assets configured on your system. Sections include asset status, top assets with highest ingestion error rate, ingestion summary, scheduled ingestion, and ingestion stats. |
| Certificates | Lists all of your certificates, status, and other general information, along with a link to configuration documentation. |
| Playbooks | Sections include playbooks failed, playbook runs by status, top failed playbooks, top playbooks ran, and a list of playbook run history. |
| System health | View status of specific hosts and nodes. Sections include memory usage, load average, CPU usage, and trends in CPU and memory usage. |