SOC operations dashboard

The SOC Operations dashboard is designed to provide insight into the security operations center (SOC) based on key metrics, workflows, and dispositions so that you can monitor the efficiency of the SOC and ensure that all security operations (detections, analysis, and responses) are on track.

Dashboard panels

Key metrics

Panel Description and default search
Mean Time to Triage Displays the average time (in minutes) to triage or prioritize the investigation of a notable over the duration of a specified time period. Also, displays a trendline (in absolute value) that indicates how the mean time taken to triage the notable compares to the previous mean time taken to triage the notable over the same time period. For example, the trendline may display that the mean time to triage a notable over the last 7 days is 0.5% up or down over the mean time taken to triage the notable during the previous 7 day time period. For more information, see Triage findings in Splunk Enterprise Security.
Mean Time to Resolution Displays the average time (in minutes) taken by the notable to reach its configured end status over the duration of a specified time period. Also, displays a trendline (in absolute value) that indicates how the mean time taken by the notable to reach its configured end status compares to the previous mean time taken by the notable to reach its configured end status over the same time period.
Investigations Created Displays the number of investigations created in the SOC over the duration of a specified time period. Also, displays a trendline (in absolute value) that indicates how the mean number of investigations created compares to the previous mean number of investigations created over the same time period. For more information, see Start an investigation in Splunk Enterprise Security.

Workflow

Panel Description and default search
Assigned Notables Over Time Displays a comparison graph of assigned versus unassigned notables over the duration of a specified time period.
Notables in End State by Time Displays a comparison graph for notables that are assigned versus the notables that have been resolved i.e. reached the configured end state over the duration of a specified time period.
Analyst Close Rate Over Time Displays a comparison graph for assigned open versus assigned closed notables by an analyst over the duration of a specified time period.

Dispositions

Panel Description and default search
Dispositions Over Time Displays a distribution of the various dispositions that are assigned to notables over the duration of a specified time period. This visualization provides insight into the number of notables that are false positives versus notables that are true positives. For more information on assigning dispositions to notables, see Add a disposition to a finding or an investigation.
Sources Contributing to False Positive - Incorrect Analytic Logic Displays a list of sources, which generated notables that have the disposition False Positive - Incorrect Analytic Logic over the duration of a specified time period.
Sources Contributing to False Positive - Inaccurate Data Displays a list of sources, which generated notables that have the disposition False Positive - Inaccurate Data over the duration of a specified time period.
Sources Contributing to True Positive - Suspicious Activity Displays a list of sources, which generated notables that have the disposition True Positive - Suspicious over the duration of a specified time period.
Sources Contributing to True Positive - Suspicious but Expected Displays a list of sources, which generated notables that have the disposition True Positives - Suspicious, but Expected over the duration of a specified time period.

Note: For key indicator panels and time chart visualizations on the SOC Operations dashboard, some arguments in the underlying SPL searches may be dynamically updated based on the time range selected on the dashboard UI.