<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enterprise Security sourcetypes in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-specify-Enterprise-Security-sourcetypes/m-p/593781#M12236</link>
    <description>&lt;P&gt;What is the name of the Correlational Search that is having this issue?&lt;/P&gt;&lt;P&gt;If you are sure that the index and sourcetype has the data it requires, is it possible that you are missing a Technical Addon that maps the data into a CIM format?&lt;/P&gt;</description>
    <pubDate>Thu, 14 Apr 2022 12:56:58 GMT</pubDate>
    <dc:creator>Stefanie</dc:creator>
    <dc:date>2022-04-14T12:56:58Z</dc:date>
    <item>
      <title>How to specify Enterprise Security sourcetypes?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-specify-Enterprise-Security-sourcetypes/m-p/593679#M12229</link>
      <description>&lt;P&gt;I have correlation searches in ES that are not generating notable events as they should be. When I click on content management and find a search that isn't working, it shows a green check mark next to the index but a red exclamation mark next to the sourcetype, saying that there have been no events in that sourcetype for the last 24 hours.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I want to know if this is the cause of my issue, and what I can do to troubleshoot it. I see there are events in the sourcetype/index specified, and they are visible in the search box of the ES app.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 15:11:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-specify-Enterprise-Security-sourcetypes/m-p/593679#M12229</guid>
      <dc:creator>TheBravoSierra</dc:creator>
      <dc:date>2022-04-14T15:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-specify-Enterprise-Security-sourcetypes/m-p/593781#M12236</link>
      <description>&lt;P&gt;What is the name of the Correlational Search that is having this issue?&lt;/P&gt;&lt;P&gt;If you are sure that the index and sourcetype has the data it requires, is it possible that you are missing a Technical Addon that maps the data into a CIM format?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2022 12:56:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-specify-Enterprise-Security-sourcetypes/m-p/593781#M12236</guid>
      <dc:creator>Stefanie</dc:creator>
      <dc:date>2022-04-14T12:56:58Z</dc:date>
    </item>
  </channel>
</rss>

