实时事件响应看板

原名:building-incident-response-dashboard

在 Splunk 或 Elastic 中构建实时事件响应仪表板。

分类
开发提效
版本
v1.0
作者
弈韬(@ra1nzzz)
下载
2
收藏
0
发布
2026-08-18
更新
2026-08-22
TRACE 评分
3.4 / 5

内容概览

Use this skill when: - IR teams need real-time dashboards during active incidents for coordination and tracking - SOC leadership requires operational dashboards showing incident status and analyst workload - Post-incident reviews need visual timelines and impact assessments - Executive briefings require high-level incident metrics and trend analysis Do not use for day-to-day SOC monitoring dashboards (use Incident Review instead) — IR dashboards are designed for active incident coordination and management reporting. - SIEM platform (Splunk with Dashboard Studio, Elastic Kibana, or Grafana) - Notable event and incident data in SIEM (Splunk ES incident review index) - Ticketing system integration (ServiceNow, Jira) for remediation tracking - Asset and identity lookup tables for context enrichment - Dashboard publishing access for SOC team and management distribution Build a Splunk Dashboar…

查看 SKILL 详情