Splunk Enterprise Security

How to organize my columns, in a table, by urgency for tracking KPI for notable events?

mmcg
Explorer

I would like to organize a table for tracking KPI for notable events like so:

No. of Critical No. of High No. of Medium   No. of Low  TOTAL
KPI (%)                 KPI (%)...
# in SLA
# Out 
# open/unassigned. 

But I'm struggling to find a way to organize my columns by the urgency.

Is it possible to achieve this output with a single search, or do I have to create a new panel for each severity?

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...