实时事件响应看板
原名:building-incident-response-dashboard
在 Splunk 或 Elastic 中构建实时事件响应仪表板。
- 分类
- 开发提效
- 版本
- v1.0
- 作者
- 弈韬(@ra1nzzz)
- 下载
- 2
- 收藏
- 0
- 发布
- 2026-08-18
- 更新
- 2026-08-22
- TRACE 评分
- 3.4 / 5
内容概览
Use this skill when: - IR teams need real-time dashboards during active incidents for coordination and tracking - SOC leadership requires operational dashboards showing incident status and analyst workload - Post-incident reviews need visual timelines and impact assessments - Executive briefings require high-level incident metrics and trend analysis Do not use for day-to-day SOC monitoring dashboards (use Incident Review instead) — IR dashboards are designed for active incident coordination and management reporting. - SIEM platform (Splunk with Dashboard Studio, Elastic Kibana, or Grafana) - Notable event and incident data in SIEM (Splunk ES incident review index) - Ticketing system integration (ServiceNow, Jira) for remediation tracking - Asset and identity lookup tables for context enrichment - Dashboard publishing access for SOC team and management distribution Build a Splunk Dashboar…