<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot get Infosec App to work in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-get-Infosec-App-to-work/m-p/473424#M58183</link>
    <description>&lt;P&gt;Hi @wbueno2, as others pointed out, CIM compliant data is a must for the InfoSec app to work. Here is what you may want to do: &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Review the &lt;A href="https://splunkbase.splunk.com/app/4240/#/details"&gt;installation instructions&lt;/A&gt; for the InfoSec app

&lt;UL&gt;
&lt;LI&gt;Check whether you have the &lt;A href="https://splunkbase.splunk.com/app/1621/"&gt;CIM add-on&lt;/A&gt; installed &lt;/LI&gt;
&lt;LI&gt;Accelerate the data models (Settings&amp;gt;Data Models) listed in the instructions&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;Check whether you use CIM-compliant add-ons for your data. In your case, for example, you should have &lt;A href="https://splunkbase.splunk.com/app/1620/"&gt;Cisco ASA&lt;/A&gt; and &lt;A href="https://splunkbase.splunk.com/app/742/"&gt;Windows&lt;/A&gt; add-ons installed on your Splunk server (or Search Heads in distributed environment). Check installation instructions for the add-ons. &lt;/LI&gt;
&lt;LI&gt;Go to InfoSec app &amp;gt; Health and Stats and check the following two tables:

&lt;UL&gt;
&lt;LI&gt;"Data Models Used by the InfoSec App: Events in Past 24 Hours"&lt;/LI&gt;
&lt;LI&gt;"All Data Models: Status"
(You may need to wait from 5 minutes to an hour or more depending how much data you are sending to Splunk and how behind data models are on acceleration) &lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;If you see only red in the tables above, your data is not CIM compliant and/or data models are not accelerated. This is where you may want to look at these two resources:

&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://youtu.be/QTklD7OiN74"&gt;Overview of Splunk CIM&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/CIM/4.14.0/User/Overview"&gt;Official Splunk CIM doc&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
    <pubDate>Fri, 03 Jan 2020 17:26:00 GMT</pubDate>
    <dc:creator>igifrin_splunk</dc:creator>
    <dc:date>2020-01-03T17:26:00Z</dc:date>
    <item>
      <title>Cannot get Infosec App to work</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-get-Infosec-App-to-work/m-p/473419#M58178</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;

&lt;P&gt;I would like to know what I´m doing wrong? I´m sending all logs sugested by the app but it seems something is wrong. Can anyone please help me to get this sorted?&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/8138iDD7428A1047E0FB7/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 13:29:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-get-Infosec-App-to-work/m-p/473419#M58178</guid>
      <dc:creator>wbueno2</dc:creator>
      <dc:date>2019-12-30T13:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot get Infosec App to work</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-get-Infosec-App-to-work/m-p/473420#M58179</link>
      <description>&lt;P&gt;What are you expecting to see?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 14:14:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-get-Infosec-App-to-work/m-p/473420#M58179</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-12-30T14:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot get Infosec App to work</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-get-Infosec-App-to-work/m-p/473421#M58180</link>
      <description>&lt;P&gt;There´s no data coming to infosec.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 15:12:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-get-Infosec-App-to-work/m-p/473421#M58180</guid>
      <dc:creator>wbueno2</dc:creator>
      <dc:date>2019-12-30T15:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot get Infosec App to work</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-get-Infosec-App-to-work/m-p/473422#M58181</link>
      <description>&lt;P&gt;Have you reviewed the setup requirements? Must be CIM compliant data with acceleration on required data models...&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/4240/#/details"&gt;https://splunkbase.splunk.com/app/4240/#/details&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 15:26:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-get-Infosec-App-to-work/m-p/473422#M58181</guid>
      <dc:creator>mydog8it</dc:creator>
      <dc:date>2019-12-30T15:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot get Infosec App to work</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-get-Infosec-App-to-work/m-p/473423#M58182</link>
      <description>&lt;P&gt;How can I make sure the data is coming is CIM compliant? Apart from that I followed all the steps.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 17:10:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-get-Infosec-App-to-work/m-p/473423#M58182</guid>
      <dc:creator>wbueno2</dc:creator>
      <dc:date>2019-12-30T17:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot get Infosec App to work</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-get-Infosec-App-to-work/m-p/473424#M58183</link>
      <description>&lt;P&gt;Hi @wbueno2, as others pointed out, CIM compliant data is a must for the InfoSec app to work. Here is what you may want to do: &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Review the &lt;A href="https://splunkbase.splunk.com/app/4240/#/details"&gt;installation instructions&lt;/A&gt; for the InfoSec app

&lt;UL&gt;
&lt;LI&gt;Check whether you have the &lt;A href="https://splunkbase.splunk.com/app/1621/"&gt;CIM add-on&lt;/A&gt; installed &lt;/LI&gt;
&lt;LI&gt;Accelerate the data models (Settings&amp;gt;Data Models) listed in the instructions&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;Check whether you use CIM-compliant add-ons for your data. In your case, for example, you should have &lt;A href="https://splunkbase.splunk.com/app/1620/"&gt;Cisco ASA&lt;/A&gt; and &lt;A href="https://splunkbase.splunk.com/app/742/"&gt;Windows&lt;/A&gt; add-ons installed on your Splunk server (or Search Heads in distributed environment). Check installation instructions for the add-ons. &lt;/LI&gt;
&lt;LI&gt;Go to InfoSec app &amp;gt; Health and Stats and check the following two tables:

&lt;UL&gt;
&lt;LI&gt;"Data Models Used by the InfoSec App: Events in Past 24 Hours"&lt;/LI&gt;
&lt;LI&gt;"All Data Models: Status"
(You may need to wait from 5 minutes to an hour or more depending how much data you are sending to Splunk and how behind data models are on acceleration) &lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;LI&gt;If you see only red in the tables above, your data is not CIM compliant and/or data models are not accelerated. This is where you may want to look at these two resources:

&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://youtu.be/QTklD7OiN74"&gt;Overview of Splunk CIM&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://docs.splunk.com/Documentation/CIM/4.14.0/User/Overview"&gt;Official Splunk CIM doc&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Fri, 03 Jan 2020 17:26:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cannot-get-Infosec-App-to-work/m-p/473424#M58183</guid>
      <dc:creator>igifrin_splunk</dc:creator>
      <dc:date>2020-01-03T17:26:00Z</dc:date>
    </item>
  </channel>
</rss>

