Create and manage key indicator searches in Splunk Enterprise Security

Configure key indicator searches on Content Management in Splunk Enterprise Security. Use the filters to select a type of key indicator to view only key indicator searches.

Create a custom key indicator search

Schedule a key indicator search

Edit a key indicator search

Customize the error message for key indicator searches

  1. From the ES menu bar, select Security content then Content management.
  2. In the Type drop down, filter by Key Indicator Search.
  3. Select a key indicator search.
  4. Select the key indicator search for which you want to customize the error message.
    This opens the Edit Key Indicator Search dialog.
  5. Scroll down to the Error Configuration section of the Key Indicator Search editor.
  6. Edit the error message.

Add a dependent search to a key indicator search