> ## Documentation Index
> Fetch the complete documentation index at: https://bloodhound.specterops.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Use the BloodHound Enterprise Splunk app

> Learn how to use the BloodHound Enterprise Splunk app to visualize and analyze BloodHound Enterprise data within Splunk.

<img noZoom src="https://mintcdn.com/specterops/tTIczgde9H07oLXf/assets/enterprise-edition-pill-tag.svg?fit=max&auto=format&n=tTIczgde9H07oLXf&q=85&s=b682a26b342bde12302ec829e265bdb6" alt="Applies to BloodHound Enterprise only" width="225" height="45" data-path="assets/enterprise-edition-pill-tag.svg" />

The BloodHound Enterprise Splunk app provides several dashboards that allow you to gain insights into your environments. These dashboards visualize data ingested from various BloodHound Enterprise data inputs, including posture statistics, attack paths, audit logs, and tier zero assets.

<Tip>You configure the [data inputs](/integrations/splunk/siem/install#configure-the-app-required) for these dashboards during the installation and configuration of the BloodHound Enterprise Splunk app.</Tip>

Each dashboard offers filtering options to help you analyze data based on different parameters such as BloodHound Enterprise tenant, domain, and time range. Dashboards also provide standard Splunk controls for managing dashboards and visualizations. See the Splunk [documentation](https://docs.splunk.com/Documentation/Splunk/latest/Viz/Dashboards) for more information.

## Dashboard Summary

Use this overview to find the right dashboard quickly. Detailed panels and filters are documented in each subsection below.

| Dashboard        | Purpose                                                                                                                     | Data Input         |
| ---------------- | --------------------------------------------------------------------------------------------------------------------------- | ------------------ |
| Posture History  | Monitor posture trends (exposure, findings, attack paths, Tier Zero assets) over time for selected tenants and environments | Posture Statistics |
| Attack Paths     | Analyze attack paths across domains, including principals involved, exposure levels, severity, and associated findings      | Attack Paths       |
| Audit Logs       | Filter and analyze administrative and system audit events collected by BloodHound Enterprise                                | Audit Logs         |
| Tier Zero Assets | Inventory Tier Zero assets across domains and analyze their distribution and details                                        | Tier Zero Assets   |

## Posture History

The **Posture History** dashboard helps you monitor [posture](/analyze-data/findings/posture) trends over time for your BloodHound Enterprise tenants and environments. It provides insights about trends in exposure levels, findings, attack paths, and Tier Zero assets.

All panels in this dashboard use data from the **Posture Statistics** data input and share the following filters:

* BloodHound Tenant
* Environment
* Time Range

The following sections describe each panel on this dashboard.

### Exposure

This panel shows the trend (by percentage) of exposure over time for the selected BloodHound tenant(s) and environment(s) within a specified time range.

<Frame>
  <img src="https://mintcdn.com/specterops/HbCgAIdv_OAN1gyR/images/integrations/splunk/siem/posture-exposure-percentage.png?fit=max&auto=format&n=HbCgAIdv_OAN1gyR&q=85&s=2adf59126950e370f8dacc45b0c391b4" alt="A view of the Posture History Exposure panel in the BloodHound Enterprise Splunk app" width="2908" height="876" data-path="images/integrations/splunk/siem/posture-exposure-percentage.png" />
</Frame>

### Findings

This panel shows the trend (by count) of posture findings over time for the selected BloodHound tenant(s) and environment(s) within a specified time range.

<Frame>
  <img src="https://mintcdn.com/specterops/HbCgAIdv_OAN1gyR/images/integrations/splunk/siem/posture-findings.png?fit=max&auto=format&n=HbCgAIdv_OAN1gyR&q=85&s=2400688a410cfddc7d0bb6308400ae0c" alt="A view of the Posture History Findings panel in the BloodHound Enterprise Splunk app" width="2908" height="876" data-path="images/integrations/splunk/siem/posture-findings.png" />
</Frame>

### Attack Path

This panel shows the trend (by count) of critical attack paths over time for the selected BloodHound tenant(s) and environment(s) within a specified time range.

<Frame>
  <img src="https://mintcdn.com/specterops/HbCgAIdv_OAN1gyR/images/integrations/splunk/siem/posture-attack-path.png?fit=max&auto=format&n=HbCgAIdv_OAN1gyR&q=85&s=31ec0262e48816f303e8916da9397dc2" alt="A view of the Posture History Attack Path panel in the BloodHound Enterprise Splunk app" width="2908" height="876" data-path="images/integrations/splunk/siem/posture-attack-path.png" />
</Frame>

### Assets

This panel shows the trend (by count) of Tier Zero assets over time for the selected BloodHound tenant(s) and environment(s) within a specified time range.

<Frame>
  <img src="https://mintcdn.com/specterops/HbCgAIdv_OAN1gyR/images/integrations/splunk/siem/posture-assets.png?fit=max&auto=format&n=HbCgAIdv_OAN1gyR&q=85&s=3e673a86f4dabd7a822a1b3ed526dd54" alt="A view of the Posture History Assets panel in the BloodHound Enterprise Splunk app" width="2908" height="876" data-path="images/integrations/splunk/siem/posture-assets.png" />
</Frame>

## Attack Paths

The **Attack Paths** dashboards allows you to analyze attack paths identified by BloodHound Enterprise across your configured domains. It provides detailed information about principals that can compromise the Tier Zero Privilege Zone, their exposure levels, severity, and associated findings.

### Overview

This dashboard summarizes attack path findings (by count, severity, and frequency) across selected BloodHound tenant(s) and environment(s) within a specified time range.

All panels in this dashboard use data from the **Attack Paths** data input and share the following filters:

* BloodHound Tenant
* Environment
* Severity
* Time Range

#### Total Domain Wise Attack Paths per Domain

This panel shows the total count of attack paths (by domain) identified in the selected BloodHound tenant(s) and environment(s) within a specified time range.

<Frame>
  <img src="https://mintcdn.com/specterops/1w44dPwHX0hJEUPb/images/integrations/splunk/siem/attack-paths-total.png?fit=max&auto=format&n=1w44dPwHX0hJEUPb&q=85&s=f90136c58f548545453f3aae6d73100c" alt="A view of the Attack Paths Total Domain Wise Attack Paths per Domain panel in the BloodHound Enterprise Splunk app" width="1452" height="584" data-path="images/integrations/splunk/siem/attack-paths-total.png" />
</Frame>

#### Severity Breakdown

This panel shows the distribution of findings (by severity) for the selected BloodHound tenant(s) and environment(s) within a specified time range.

<Frame>
  <img src="https://mintcdn.com/specterops/1w44dPwHX0hJEUPb/images/integrations/splunk/siem/attack-paths-severity.png?fit=max&auto=format&n=1w44dPwHX0hJEUPb&q=85&s=34b7ff21fa1fc81a3d1d85b71c462657" alt="A view of the Attack Paths Severity Breakdown panel in the BloodHound Enterprise Splunk app" width="1452" height="584" data-path="images/integrations/splunk/siem/attack-paths-severity.png" />
</Frame>

#### Top 5 Non-Tier Zero Principals Involved

This panel shows the top five non-tier Zero principals most frequently involved in attack path findings for the selected BloodHound tenant(s) and environment(s) within a specified time range.

<Frame>
  <img src="https://mintcdn.com/specterops/1w44dPwHX0hJEUPb/images/integrations/splunk/siem/attack-paths-top-principals.png?fit=max&auto=format&n=1w44dPwHX0hJEUPb&q=85&s=19307011a9da7df5f19f35e8f352e2ff" alt="A view of the Attack Paths Top 5 Non-Tier Zero Principals Involved panel in the BloodHound Enterprise Splunk app" width="1452" height="460" data-path="images/integrations/splunk/siem/attack-paths-top-principals.png" />
</Frame>

#### Top 5 Most Common Findings

This panel shows the top five most common finding types (by frequency) for the selected BloodHound tenant(s) and environment(s) within a specified time range.

<Frame>
  <img src="https://mintcdn.com/specterops/1w44dPwHX0hJEUPb/images/integrations/splunk/siem/attack-paths-top-findings-common.png?fit=max&auto=format&n=1w44dPwHX0hJEUPb&q=85&s=7bb08d8f9262f4ab3bf8ff0fd268e5cf" alt="A view of the Attack Paths Top 5 Most Common Findings panel in the BloodHound Enterprise Splunk app" width="1452" height="460" data-path="images/integrations/splunk/siem/attack-paths-top-findings-common.png" />
</Frame>

#### Top 5 Most Common Findings Per Environment

This panel shows the top five most common finding types (by frequency) per environment for the selected BloodHound tenant(s) and environment(s) within a specified time range.

<Frame>
  <img src="https://mintcdn.com/specterops/1w44dPwHX0hJEUPb/images/integrations/splunk/siem/attack-paths-top-findings-environment.png?fit=max&auto=format&n=1w44dPwHX0hJEUPb&q=85&s=e22767107c61943bfd9c07518c6e67a5" alt="A view of the Attack Paths Top 5 Most Common Findings Per Environment panel in the BloodHound Enterprise Splunk app" width="2910" height="1256" data-path="images/integrations/splunk/siem/attack-paths-top-findings-environment.png" />
</Frame>

#### Top 10 Attack Paths by Exposure

This panel shows the top ten attack paths (by exposure percentage) for the selected BloodHound tenant(s) and environment(s) within a specified time range.

<Frame>
  <img src="https://mintcdn.com/specterops/1w44dPwHX0hJEUPb/images/integrations/splunk/siem/attack-paths-top-ten.png?fit=max&auto=format&n=1w44dPwHX0hJEUPb&q=85&s=d34cbd645f81b6fe5563f2fbdaae135d" alt="A view of the Attack Paths Top 10 Attack Paths by Exposure panel in the BloodHound Enterprise Splunk app" width="2910" height="1062" data-path="images/integrations/splunk/siem/attack-paths-top-ten.png" />
</Frame>

<Note>Details also include links to BloodHound Enterprise remediation documentation.</Note>

### Details

This dashboard provides more granular details about specific attack paths identified by BloodHound Enterprise. It allows you to investigate principals involved in attack paths, their exposure levels, and associated findings.

All panels in this dashboard use data from the **Attack Paths** data input and share the following filters:

* BloodHound Tenant
* Environment
* Attack Paths
* Severity
* Time Range

#### Principals

This panel shows all principals based on the selected filters.

It provides the following detailed information about each principal:

|                         |                      |
| ----------------------- | -------------------- |
| Non-Tier Zero Principal | Impact Count         |
| Tier Zero Principal     | SAM Account Name     |
| Display Name            | Sensitive            |
| Finding Name            | Last Logon           |
| Distinguished Name      | Last Logon Timestamp |
| Severity Level          | Created Timestamp    |
| Impact Percentage       | First Seen           |
| Last Updated            |                      |

<Frame>
  <img src="https://mintcdn.com/specterops/1w44dPwHX0hJEUPb/images/integrations/splunk/siem/attack-path-details-principals.png?fit=max&auto=format&n=1w44dPwHX0hJEUPb&q=85&s=eb74729ce941e14713d5ab96c3fb2b09" alt="A view of the Attack Paths Details Principals panel in the BloodHound Enterprise Splunk app" width="2910" height="766" data-path="images/integrations/splunk/siem/attack-path-details-principals.png" />
</Frame>

#### Maximum Exposure Percentage

This panel shows the highest exposure (by percentage) for the specified filters.

<Frame>
  <img src="https://mintcdn.com/specterops/1w44dPwHX0hJEUPb/images/integrations/splunk/siem/attack-path-details-max-exposure.png?fit=max&auto=format&n=1w44dPwHX0hJEUPb&q=85&s=d657b13502dfe274b0afd62b81226d54" alt="A view of the Attack Paths Details Maximum Exposure Percentage panel in the BloodHound Enterprise Splunk app" width="1450" height="648" data-path="images/integrations/splunk/siem/attack-path-details-max-exposure.png" />
</Frame>

#### Total Number of Findings

This panel shows the total number of findings (by count) for the specified filters.

<Frame>
  <img src="https://mintcdn.com/specterops/1w44dPwHX0hJEUPb/images/integrations/splunk/siem/attack-path-details-total-findings.png?fit=max&auto=format&n=1w44dPwHX0hJEUPb&q=85&s=62412db16683638dad0d9cf6618abab5" alt="A view of the Attack Paths Details Total Number of Findings panel in the BloodHound Enterprise Splunk app" width="1450" height="648" data-path="images/integrations/splunk/siem/attack-path-details-total-findings.png" />
</Frame>

### Finding Trends

This dashboard provides trend analysis of attack path findings over time. It helps you understand how the exposure and frequency of findings change over time for selected BloodHound tenant(s) and environment(s) within a specified time range.

All panels in this dashboard use data from the **Attack Paths** data input and share the following filters:

* BloodHound Tenant
* Environment
* Category
* Time Period

#### Attack Path Trends

This panel shows the trend (by category) of attack paths over time for the selected BloodHound tenant(s) and environment(s) within a specified time range.

Categories include:

* Tier Zero
* Kerberos
* AD Certificate Services
* Relay attacks
* Least privilege
* Entra ID
* Hybrid
* Microsoft Graph
* Azure Resource Manager

<Frame>
  <img src="https://mintcdn.com/specterops/1w44dPwHX0hJEUPb/images/integrations/splunk/siem/attack-paths-finding-trends.png?fit=max&auto=format&n=1w44dPwHX0hJEUPb&q=85&s=a540649124b3b01816d4eeddb211447e" alt="A view of the Attack Paths Finding Trends panel in the BloodHound Enterprise Splunk app" width="2914" height="770" data-path="images/integrations/splunk/siem/attack-paths-finding-trends.png" />
</Frame>

## Audit Logs

This dashboard allows you to filter and analyze administrative and system audit events collected by BloodHound Enterprise.

All panels in this dashboard use data from the **Audit Logs** data input and share the following filters:

* BloodHound Tenant
* Event Type
* Actor Name
* Time Range

The audit log table provides the following information about each event:

|                   |                     |
| ----------------- | ------------------- |
| ID                | Created At          |
| Actor ID          | Actor Name          |
| Actor Email       | Action (event type) |
| Fields            | Request ID          |
| Source IP address | Commit ID           |
| Status            |                     |

<Frame>
  <img src="https://mintcdn.com/specterops/1w44dPwHX0hJEUPb/images/integrations/splunk/siem/audit-logs.png?fit=max&auto=format&n=1w44dPwHX0hJEUPb&q=85&s=75b1334189f4230a364359e9b4f955a1" alt="A view of the Audit Logs dashboard in the BloodHound Enterprise Splunk app" width="2914" height="726" data-path="images/integrations/splunk/siem/audit-logs.png" />
</Frame>

<Tip>Clicking on any row in the Audit Logs table will open a detailed view of the selected audit event, providing additional context and information.</Tip>

## Tier Zero Assets

This dashboard provides an inventory of Tier Zero assets identified by BloodHound Enterprise across your configured domains. It helps you analyze the distribution and details of Tier Zero assets.

All panels in this dashboard use data from the **Tier Zero Assets** data input and share the following filters:

* BloodHound Tenant
* Environment
* Type

### Tier Zero Assets List

This panel provides a detailed listing of Tier Zero assets across your configured domains. It includes the following information about each asset:

* Name
* Environment
* Type
* Object ID

<Frame>
  <img src="https://mintcdn.com/specterops/HbCgAIdv_OAN1gyR/images/integrations/splunk/siem/tier-zero-assets-list.png?fit=max&auto=format&n=HbCgAIdv_OAN1gyR&q=85&s=556f7a7d06dae80e9d29964b4e1d6332" alt="A view of the Tier Zero Assets List panel in the BloodHound Enterprise Splunk app" width="2914" height="770" data-path="images/integrations/splunk/siem/tier-zero-assets-list.png" />
</Frame>

### Tier Zero Assets Distribution By Environment

This panel shows how Tier Zero assets are distributed across the selected BloodHound tenant(s), environment(s), and asset type(s).

<Frame>
  <img src="https://mintcdn.com/specterops/HbCgAIdv_OAN1gyR/images/integrations/splunk/siem/tier-zero-assets-distribution.png?fit=max&auto=format&n=HbCgAIdv_OAN1gyR&q=85&s=c1527ee76fa7f7db0535f59acd1c676b" alt="A view of the Tier Zero Assets Distribution By Environment panel in the BloodHound Enterprise Splunk app" width="2912" height="554" data-path="images/integrations/splunk/siem/tier-zero-assets-distribution.png" />
</Frame>

## Search

See the Splunk [documentation](https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.0/search-overview/get-started-with-search) for details about using Splunk Search to create custom queries and visualizations based on BloodHound Enterprise data.

## Administration

See [install and configure](/integrations/splunk/siem/install) the BloodHound Enterprise Splunk app for details about configuring data inputs and other administrative tasks.
