Splunk
  • Splunk Enterprise

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    Splunk Cloud Platform

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    Splunkbase

    Discover, share, and install apps and add-ons with the Splunk community on Splunkbase. Publish your own or add others to your Splunk platform instance.

    DATA MANAGEMENT

    • Common Information Model
    • Data Manager
    • DB Connect
    • Edge Processing
    • Forwarders
    • Indexing
    • Ingest Monitoring
    • Stream
    • Technical Add-Ons

    SEARCH AND ANALYTICS

    • AI Toolkit
    • Alerts
    • Analytics Workspace
    • Dashboard Studio
    • Federated Search
    • Knowledge Objects
    • Search and Reporting App
    • Simple XML Dashboards
    • SPL
    • SPL2

    ADMINISTRATION

    • Cloud Platform
    • Enterprise
  • Enterprise Security

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    SOAR

    Streamline your security operations with a SOAR system that integrates orchestration, playbook automation, and case management to enhance threat response.

    Release Notes

    ENTERPRISE SECURITY

    • Enterprise Security 8
    • Enterprise Security 7
    • Mission Control
    • Security Content Update
    • User Behavior Analytics

    SOAR

    • SOAR On-Premises
    • SOAR Cloud
    • App for SOAR
    • App for SOAR Export
    • Automation Broker

    RELATED APPS

    • Attack Analyzer
    • Asset and Risk Intelligence
    • App for PCI Compliance
    • App for Fraud Analytics
    • InfoSec App
    • Security Essentials
  • IT Service Intelligence

    Prevent disruptions and optimize operations when you monitor and analyze your IT service with predictive analytics and machine learning.

    Release Notes

    Content Packs

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    ITSI

    • Event Analytics
    • Entity Integration
    • Modules
    • Service Insights
    • REST APIs

    IT Ops

    • IT Essentials Work
    • IT Essentials Learn

    ADMINISTRATION

    • IT Service Intelligence
    • IT Essentials Work
    • Configuration File Reference

    EXTENSIONS

    • SAP Solutions
    • Infrastructure Monitoring Add-On
  • Splunk Observability Cloud

    Gain end-to-end visibility, troubleshoot in real-time, and optimize performance across infrastructure, applications, and user interfaces.

    Release Notes

    MONITORING

    • Alerts and Detectors
    • Application Performance Monitoring
    • Infrastructure Monitoring
    • Observability Cloud for Mobile
    • On-Call

    DATA MANAGEMENT

    • AI Assistant
    • Dashboards and Charts
    • Integrations
    • Log Observer Connect
    • Metrics, Metadata, and Events
    • OpenTelemetry Collector
    • SignalFlow Analytics
    • Search Reference

    ADMINISTRATION

    • Organization Management
    • FedRamp Support
    • App Development
    • API Reference
  • AppDynamics SaaS

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    AppDynamics On-Premises

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    SAP Agent

    An on-premises solution using AppDynamics On-Premises or Appdynamics Virtual Appliance (self hosted).

    Release Notes

    ESSENTIALS

    • Alert and Respond
    • Agent Management
    • Dashboards and Reports
    • Extensions
    • Licensing
    • Tag Management

    MONITORING

    • Analytics
    • Application Security Monitoring
    • Application Performance Monitoring
    • Database Visibility
    • End User Monitoring
    • Infrastructure Visibility

    ADMINISTRATION

    • AppDynamics on-premises
    • AppDynamics Virtual Appliance
  • Developer Documentation

    Build and deliver apps and integrations with SDKs, APIs and tools.

    Splunkbase

    Access and share apps and add-ons with the Splunk community on Splunkbase. Publish your own apps, or download and install others on your Splunk platform instance.

    PLATFORM

    • Developer Guide
    • APIs and tools
    • Tutorials
    • Downloads
    • Examples

    OBSERVABILITY

    • Developer Guide
    • REST APIs

    REFERENCE

    • Python 3 Migration
    • SOAR
    • SDK Reference
    • UI Toolkit
  • Resources

    Explore information on best practices, connect with community, or contact support.

    REFERENCE

    • Configuration Files Reference
    • REST APIs
    • SPL Reference
    • Splunk Style Guide
    • Search Tutorial
    • Validated Architectures

    Learn More

    • Free Trials & Downloads
    • Splunk Community
    • Splunk Answers
    • SPL 2 Reference
    • Splunk Lantern

    Support

    • AppDynamics Support
    • Cisco Support
    • Product Security Advisories
    • Splunk Support
    • System Status
English Japanese
Log In Sign Up
English Japanese
Log In Sign Up
  • Splunk Enterprise

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    Splunk Cloud Platform

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    Splunkbase

    Discover, share, and install apps and add-ons with the Splunk community on Splunkbase. Publish your own or add others to your Splunk platform instance.

    DATA MANAGEMENT

    • Common Information Model
    • Data Manager
    • DB Connect
    • Edge Processing
    • Forwarders
    • Indexing
    • Ingest Monitoring
    • Stream
    • Technical Add-Ons

    SEARCH AND ANALYTICS

    • AI Toolkit
    • Alerts
    • Analytics Workspace
    • Dashboard Studio
    • Federated Search
    • Knowledge Objects
    • Search and Reporting App
    • Simple XML Dashboards
    • SPL
    • SPL2

    ADMINISTRATION

    • Cloud Platform
    • Enterprise
  • Enterprise Security

    Gain operational intelligence by collecting, indexing, and visualizing data using a powerful on-premises engine for actionable insights.

    Release Notes

    SOAR

    Streamline your security operations with a SOAR system that integrates orchestration, playbook automation, and case management to enhance threat response.

    Release Notes

    ENTERPRISE SECURITY

    • Enterprise Security 8
    • Enterprise Security 7
    • Mission Control
    • Security Content Update
    • User Behavior Analytics

    SOAR

    • SOAR On-Premises
    • SOAR Cloud
    • App for SOAR
    • App for SOAR Export
    • Automation Broker

    RELATED APPS

    • Attack Analyzer
    • Asset and Risk Intelligence
    • App for PCI Compliance
    • App for Fraud Analytics
    • InfoSec App
    • Security Essentials
  • IT Service Intelligence

    Prevent disruptions and optimize operations when you monitor and analyze your IT service with predictive analytics and machine learning.

    Release Notes

    Content Packs

    Collect, index, and visualize your data in the cloud for better operational intelligence.

    Release Notes

    ITSI

    • Event Analytics
    • Entity Integration
    • Modules
    • Service Insights
    • REST APIs

    IT Ops

    • IT Essentials Work
    • IT Essentials Learn

    ADMINISTRATION

    • IT Service Intelligence
    • IT Essentials Work
    • Configuration File Reference

    EXTENSIONS

    • SAP Solutions
    • Infrastructure Monitoring Add-On
  • Splunk Observability Cloud

    Gain end-to-end visibility, troubleshoot in real-time, and optimize performance across infrastructure, applications, and user interfaces.

    Release Notes

    MONITORING

    • Alerts and Detectors
    • Application Performance Monitoring
    • Infrastructure Monitoring
    • Observability Cloud for Mobile
    • On-Call

    DATA MANAGEMENT

    • AI Assistant
    • Dashboards and Charts
    • Integrations
    • Log Observer Connect
    • Metrics, Metadata, and Events
    • OpenTelemetry Collector
    • SignalFlow Analytics
    • Search Reference

    ADMINISTRATION

    • Organization Management
    • FedRamp Support
    • App Development
    • API Reference
  • AppDynamics SaaS

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    AppDynamics On-Premises

    Monitor business application performance for cloud environments and IT infrastructure.

    Release Notes

    SAP Agent

    An on-premises solution using AppDynamics On-Premises or Appdynamics Virtual Appliance (self hosted).

    Release Notes

    ESSENTIALS

    • Alert and Respond
    • Agent Management
    • Dashboards and Reports
    • Extensions
    • Licensing
    • Tag Management

    MONITORING

    • Analytics
    • Application Security Monitoring
    • Application Performance Monitoring
    • Database Visibility
    • End User Monitoring
    • Infrastructure Visibility

    ADMINISTRATION

    • AppDynamics on-premises
    • AppDynamics Virtual Appliance
  • Developer Documentation

    Build and deliver apps and integrations with SDKs, APIs and tools.

    Splunkbase

    Access and share apps and add-ons with the Splunk community on Splunkbase. Publish your own apps, or download and install others on your Splunk platform instance.

    PLATFORM

    • Developer Guide
    • APIs and tools
    • Tutorials
    • Downloads
    • Examples

    OBSERVABILITY

    • Developer Guide
    • REST APIs

    REFERENCE

    • Python 3 Migration
    • SOAR
    • SDK Reference
    • UI Toolkit
  • Resources

    Explore information on best practices, connect with community, or contact support.

    REFERENCE

    • Configuration Files Reference
    • REST APIs
    • SPL Reference
    • Splunk Style Guide
    • Search Tutorial
    • Validated Architectures

    Learn More

    • Free Trials & Downloads
    • Splunk Community
    • Splunk Answers
    • SPL 2 Reference
    • Splunk Lantern

    Support

    • AppDynamics Support
    • Cisco Support
    • Product Security Advisories
    • Splunk Support
    • System Status
Share this page
  • LinkedIn
  • X
  • Facebook
  • Email
Splunk Enterprise Security 8
  • User Guide
    • Introduction
      • About Splunk Enterprise Security
      • Licensing for Splunk Enterprise Security
      • Get started with Splunk Enterprise Security
      • Use behavioral analytics service with Splunk Enterprise Security 7.1.0 or higher
      • Turn on behavioral analytics service on Splunk Enterprise Security
      • Use federated searches in transparent mode with Splunk Enterprise Security
      • Use Federated Analytics with Splunk Enterprise Security for threat detection in Amazon Security Lake (ASL) datasets
      • Deploy Cisco Talos Intelligence for Splunk Enterprise Security (Cloud Only)
    • Mission Control
      • Overview of Mission Control in Splunk Enterprise Security
      • Triage findings and finding groups in Splunk Enterprise Security
      • Start investigations in Splunk Enterprise Security
      • Respond to investigations with response plans in Splunk Enterprise Security
      • Add events to an investigation in Splunk Enterprise Security
      • Automate your investigation response with actions and playbooks in Splunk Enterprise Security
      • Analyze risk with risk-based alerting in Splunk Enterprise Security
      • Investigate observables related to an investigation in Splunk Enterprise Security
    • Analytics
      • Available dashboards in Splunk Enterprise Security
      • Prerequisites to use cloud security dashboards
      • Security posture dashboard
      • Executive summary dashboard
      • SOC operations dashboard
      • Audit dashboards
      • Predictive analytics dashboard
      • Access dashboards
      • Endpoint dashboards
      • Asset and identity dashboards
      • Asset and identity investigator dashboards
      • User activity dashboard
        • Access Anomalies
        • Troubleshooting
      • Risk analysis
      • Network dashboards
      • Web center and network changes dashboards
      • Port and protocol tracker dashboard
      • Protocol intelligence dashboards
      • Threat intelligence dashboards
      • Web intelligence dashboards
      • Security group dashboard
      • IAM activity dashboard
      • Network ACLs dashboard
      • Access analyzer dashboard
      • Microsoft 365 security dashboard
    • Sharing your Threat Data
      • Share Threat Data in Splunk Enterprise Security
Splunk Enterprise Security 8 › User Guide › Analytics › User activity dashboard

Troubleshooting

This dashboard references data from various data models. Without the applicable data, the dashboards will remain empty. See Troubleshoot dashboards in Splunk Enterprise Security in Administer Splunk Enterprise Security.

Share feedback about this page
Previous Access Anomalies Next Risk analysis
logo
x facebook linkedin youtube instagram
©2005-2026 Splunk Inc. All rights reserved.
Legal Privacy Website Terms of Use