Ensure that the following are available before proceeding:
- Splunk Server
- Trend Micro Email Security is already configured to use Splunk, see below links from Online Help:
To create the dashboard:
- On Splunk Admin Console, click Search.
- On the Search Box, type the following:
host="uiout.tmes.trendmicro.com" - Click the Date Range button, and select a date range. (e.g. Last 30 days).
- Click the green Search icon.
- Create a Visualization, and save it as a Report. Do the following:
- Click Visualization.
- Click Pivot, select All Fields, and then click OK.
- Under Split Rows, click + button, select Action, and do the following:
- Under Match, change to value to is in list.
- In the text box, enter "Quarantined,Delivered".
- Click Add to table.
This will show table view with the count of Delivered and Quarantined emails.
Optional Step: Click the Column Chart icon on the left pane, look for the General section, and select On for Show Data Values. - Click Save As, then click Report.
- Fill up the required fields, then click Save.
- Click View.
- Create a Dashboard and import the Report. Do the steps below:
- Click Dashboards.
- Click the Create New Dashboard button.
- Enter a Title, click Create Dashboard button.
- On Edit Dashboard page, click +Add Panel button.
- On Add Panel, expand New from Report, select the newly created Report from previous steps.
- Click Add to Dashboard button.
- Click the Save button, locatedon the upper-right .
The new dashboard can be found under the Dashboards tab.