TheIdentity Centerdashboard in Splunk Enterprise Security is the primary interface for managing and reporting on user identities, including users currently on watchlists. This dashboard allows analysts to track user behavior, alerts, and notable events related to specific user identities, with the ability to view and manage watchlist membership.
Identity Centerprovides focused visibility into user-centric data and investigations.
Access Trackeris more general for access logs and authentication events but does not provide watchlist management.
Access CenterandIdentity Trackerare not standard dashboard names in Splunk ES.
TheSplunk Enterprise Security User Guiderecommends the Identity Center for watchlist monitoring and user-focused investigations.
[Reference:, Splunk Enterprise Security User Guide, Chapter 7: Identity and Access Management, Splunk Cybersecurity Defense Analyst Study Guide, Chapter 6: User Behavior Analysis, Splunk Docs: Identity Center Overview, , , , ]
Submit