<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why did Infosec App stopped showing data? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-Infosec-App-stop-showing-data/m-p/591286#M76452</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236717"&gt;@Stefanie&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I did what you said in the data models that are needed for the infosec app.&lt;/P&gt;&lt;P&gt;Nothing changed from the health panel view. It keeps only getting data from authentication and change although the acceleration works good for all of them except for malware and web.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-03-29 16_44_06-Clipboard.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18814iCCC1381D66046CC0/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-03-29 16_44_06-Clipboard.png" alt="2022-03-29 16_44_06-Clipboard.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;One thing i saw that changed is when running the query to identify indexes that feed the data models.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;| makeresults | eval datamodels = "Authentication:Change:Endpoint:Intrusion_Detection:Network_Sessions:Network_Traffic:Malware:Endpoint.Processes:Web" | makemv delim=":" datamodels | mvexpand datamodels | map search="| makeresults | eval notfound=\"*** NO DATA FOUND ***\" | append [| tstats count from datamodel=$datamodels$ by index, sourcetype] | eventstats count as events |eval datamodel=\"$datamodels$\", index=coalesce(index,notfound)| search NOT notfound=* OR events=1 | table datamodel, index, sourcetype,count" | sort datamodel, index, sourcetype&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Now i see that network traffic and network sessions data models are no longer indicating "NO DATA FOUND" and they show 1.708.289 and 24.981 events taking them from the main index.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-03-29 16_45_24-Clipboard.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18815iD70EA1848A097FDB/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-03-29 16_45_24-Clipboard.png" alt="2022-03-29 16_45_24-Clipboard.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Still not getting that data in infosec... I also did the query that you suggested before and everything seems to be working.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-03-29 16_47_43-Search _ Splunk 8.2.4.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18816iF01667F69F10C843/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-03-29 16_47_43-Search _ Splunk 8.2.4.png" alt="2022-03-29 16_47_43-Search _ Splunk 8.2.4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I was wondering if you could post a screenshot of your network traffic data model just to adjust the settings the same way you have them.&lt;/P&gt;&lt;P&gt;When I added the "*" in the data models&amp;nbsp; i saw that your tag whitelist was blank and mine has 4 or 5 tags, is it supposed to be like that?&lt;/P&gt;&lt;P&gt;Thanks for you help.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Mar 2022 15:12:26 GMT</pubDate>
    <dc:creator>dminguez</dc:creator>
    <dc:date>2022-03-29T15:12:26Z</dc:date>
    <item>
      <title>Why did Infosec App stop showing data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-Infosec-App-stop-showing-data/m-p/590849#M76427</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have configured the Infosec App in my splunk making sure that i had all the steps in prerequisites completed. It was working for a couple of days, but it suddenly sttoped showing data. I have CIM for splunk and I can see in the health panel from infosec that the acceleration for the data models is working but I'm only recieving event and details from the Authentication and Change data model.&lt;/P&gt;
&lt;P&gt;going through this documentation &lt;A href="https://docs.splunk.com/Documentation/InfoSec/1.7.0/Admin/ValidateDataSources#Identify_tagged_events_to_configure_the_data_models" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/InfoSec/1.7.0/Admin/ValidateDataSources#Identify_tagged_events_to_configure_the_data_models&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I have checked that only Authentication and Change are getting data, not the rest. If I try to follow the guide there is no tags for the rest of the datamodels.&lt;/P&gt;
&lt;P&gt;Is this why infosec stopped working?&lt;/P&gt;
&lt;P&gt;Can anyone help with this?&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 18:55:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-Infosec-App-stop-showing-data/m-p/590849#M76427</guid>
      <dc:creator>dminguez</dc:creator>
      <dc:date>2022-03-25T18:55:29Z</dc:date>
    </item>
    <item>
      <title>Re: Why did Infosec App stopped showing data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-Infosec-App-stop-showing-data/m-p/590891#M76430</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/243605"&gt;@dminguez&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's the CIM version installed?&lt;/P&gt;&lt;P&gt;On the CIM Setup page, did you verify all the required Data Models are Accelerated?&lt;/P&gt;&lt;P&gt;Are the required indexes in the "Indexes whitelist" aligned with their respective Data Model?&lt;/P&gt;&lt;P&gt;Do you have the required TAs for your log data installed on your Search Head?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 16:11:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-Infosec-App-stop-showing-data/m-p/590891#M76430</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-03-25T16:11:17Z</dc:date>
    </item>
    <item>
      <title>Re: Why did Infosec App stopped showing data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-Infosec-App-stop-showing-data/m-p/591215#M76446</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236717"&gt;@Stefanie&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.- The CIM version I have installed is 5.0.1.&lt;/P&gt;&lt;P&gt;2.- When i accelerated the models after installing, infosec was reciecing data and after a couple of days sttoped working.&lt;/P&gt;&lt;P&gt;3.- When I check the index whitelist of each data model it's blank, Is there anything I should add to it?&lt;/P&gt;&lt;P&gt;4.- I have installed all required TA's written in the infosec App prerequisites.&lt;/P&gt;&lt;P&gt;Another thing that seems strange is that checking the data model from Settings - Knowledge - Data models. If I choose any model and edit the constraint but without modifying it,&amp;nbsp; an error shows up saying this: "In handler 'datamodeledit': Error in 'Authentication': Dataset constraints must specify at least one index. "&lt;/P&gt;&lt;P&gt;Thanks for your answers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 10:01:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-Infosec-App-stop-showing-data/m-p/591215#M76446</guid>
      <dc:creator>dminguez</dc:creator>
      <dc:date>2022-03-29T10:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why did Infosec App stopped showing data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-Infosec-App-stop-showing-data/m-p/591245#M76450</link>
      <description>&lt;P&gt;Interesting.&amp;nbsp;&lt;BR /&gt;I had the same problem with my CIM for Enterprise Security. The index whitelist was blank and I wasn't getting events anymore.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Indexes Whitelist field, can you put * ? Here's an example of mine.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 506px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18813i796D4C148642F8CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make that change and let it sit for a few minutes to run. Then try searching that datamodel using a search like&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(`cim_Authentication_indexes`) &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After verifying data is coming in, you can manually specify the indexes in the Indexes Whitelist by what's showing up using the wildcard.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know how this works for you.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 12:44:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-Infosec-App-stop-showing-data/m-p/591245#M76450</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-03-29T12:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why did Infosec App stopped showing data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-Infosec-App-stop-showing-data/m-p/591286#M76452</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236717"&gt;@Stefanie&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I did what you said in the data models that are needed for the infosec app.&lt;/P&gt;&lt;P&gt;Nothing changed from the health panel view. It keeps only getting data from authentication and change although the acceleration works good for all of them except for malware and web.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-03-29 16_44_06-Clipboard.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18814iCCC1381D66046CC0/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-03-29 16_44_06-Clipboard.png" alt="2022-03-29 16_44_06-Clipboard.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;One thing i saw that changed is when running the query to identify indexes that feed the data models.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;| makeresults | eval datamodels = "Authentication:Change:Endpoint:Intrusion_Detection:Network_Sessions:Network_Traffic:Malware:Endpoint.Processes:Web" | makemv delim=":" datamodels | mvexpand datamodels | map search="| makeresults | eval notfound=\"*** NO DATA FOUND ***\" | append [| tstats count from datamodel=$datamodels$ by index, sourcetype] | eventstats count as events |eval datamodel=\"$datamodels$\", index=coalesce(index,notfound)| search NOT notfound=* OR events=1 | table datamodel, index, sourcetype,count" | sort datamodel, index, sourcetype&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Now i see that network traffic and network sessions data models are no longer indicating "NO DATA FOUND" and they show 1.708.289 and 24.981 events taking them from the main index.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-03-29 16_45_24-Clipboard.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18815iD70EA1848A097FDB/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-03-29 16_45_24-Clipboard.png" alt="2022-03-29 16_45_24-Clipboard.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Still not getting that data in infosec... I also did the query that you suggested before and everything seems to be working.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2022-03-29 16_47_43-Search _ Splunk 8.2.4.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18816iF01667F69F10C843/image-size/large?v=v2&amp;amp;px=999" role="button" title="2022-03-29 16_47_43-Search _ Splunk 8.2.4.png" alt="2022-03-29 16_47_43-Search _ Splunk 8.2.4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I was wondering if you could post a screenshot of your network traffic data model just to adjust the settings the same way you have them.&lt;/P&gt;&lt;P&gt;When I added the "*" in the data models&amp;nbsp; i saw that your tag whitelist was blank and mine has 4 or 5 tags, is it supposed to be like that?&lt;/P&gt;&lt;P&gt;Thanks for you help.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 15:12:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-Infosec-App-stop-showing-data/m-p/591286#M76452</guid>
      <dc:creator>dminguez</dc:creator>
      <dc:date>2022-03-29T15:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Why did Infosec App stopped showing data?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-Infosec-App-stop-showing-data/m-p/591291#M76453</link>
      <description>&lt;P&gt;My settings for the Network traffic data model is the same as the screenshot above. The only difference is &lt;EM&gt;after&lt;/EM&gt;&amp;nbsp;I used the wildcard to include all indexes, waited to see what it detected, then I modified the settings to only include the indexes it was aligning to the data model using the search:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(`cim_Network_Traffic_indexes`)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;As for your tag whitelist. I removed everything. I didn't&amp;nbsp;understand why those specific tags were there when if you go to the Data Model page in Splunk and look at the Data Models, those tags did not align with the tags it wants. For example the "All Traffic" search for the Network Traffic data model is&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(`cim_Network_Traffic_indexes`) tag=network tag=communicate&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Those two tags weren't in the tag whitelist in the CIM settings. Try removing them too. Just make sure you have a screenshot or a backup before you do, incase you need them back.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 15:25:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-did-Infosec-App-stop-showing-data/m-p/591291#M76453</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-03-29T15:25:11Z</dc:date>
    </item>
  </channel>
</rss>

