Splunk offers different [[Security Information and Event Management|SIEM]] tool options: Splunk® Enterprise and Splunk® Cloud. Both allow you to review an organisation's data on dashboards. This helps security professionals manage an organisation's internal infrastructure by collecting, searching, monitoring, and analysing log data from multiple sources to obtain full visibility into an organisation’s everyday operations. #### Security posture dashboard The security posture dashboard is designed for security operations centres (SOCs). It displays the last 24 hours of an organisation’s notable security-related events and trends and allows security professionals to determine if security infrastructure and policies are performing as designed. Security analysts can use this dashboard to monitor and investigate potential threats in real time, such as suspicious network activity originating from a specific IP address. #### Executive summary dashboard The executive summary dashboard analyses and monitors the overall health of the organization over time. This helps security teams improve security measures that reduce risk. Security analysts might use this dashboard to provide high-level insights to stakeholders, such as generating a summary of security incidents and trends over a specific period of time. #### Incident review dashboard The incident review dashboard allows analysts to identify suspicious patterns that can occur in the event of an incident. It assists by highlighting higher risk items that need immediate review by an analyst. This dashboard can be very helpful because it provides a visual timeline of the events leading up to an incident. #### Risk analysis dashboard The risk analysis dashboard helps analysts identify risk for each risk object (e.g., a specific user, a computer, or an IP address). It shows changes in risk-related activity or behaviour, such as a user logging in outside of normal working hours or unusually high network traffic from a specific computer. A security analyst might use this dashboard to analyse the potential impact of vulnerabilities in critical assets, which helps analysts prioritise their risk mitigation efforts. ### Splunk searches Splunk has its own querying language called *Search Processing Language* (SPL). SPL is used to search and retrieve events from indexes using Splunk’s Search & Reporting app. An SPL search can contain many different commands and arguments. For example, you can use commands to transform your search results into a chart format or filter results for specific information.