<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why is notable index empty? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/642516#M109499</link>
    <description>&lt;P&gt;After installing the Splunk Enterprise Security (ES) app using the splunk-enterprise-security_701.spl file, I noticed that the "Security Posture" dashboard was empty and searching for index=notable returned no results. Upon further investigation, I discovered that there was no inputs.conf file present in the /opt/splunk/etc/apps/SplunkEnterpriseSecuritySuite/local directory&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Mon, 08 May 2023 13:15:37 GMT</pubDate>
    <dc:creator>NeedNotToKnow</dc:creator>
    <dc:date>2023-05-08T13:15:37Z</dc:date>
    <item>
      <title>Why is notable index empty?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/642516#M109499</link>
      <description>&lt;P&gt;After installing the Splunk Enterprise Security (ES) app using the splunk-enterprise-security_701.spl file, I noticed that the "Security Posture" dashboard was empty and searching for index=notable returned no results. Upon further investigation, I discovered that there was no inputs.conf file present in the /opt/splunk/etc/apps/SplunkEnterpriseSecuritySuite/local directory&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 08 May 2023 13:15:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/642516#M109499</guid>
      <dc:creator>NeedNotToKnow</dc:creator>
      <dc:date>2023-05-08T13:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: notable index empty</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/642518#M109501</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/256524"&gt;@NeedNotToKnow&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;before installing and configuring ES, it's a best practice to check that you're receiving all the data flows of your perimeter and that these data flows are all normalized.&lt;/P&gt;&lt;P&gt;You can check normalization checking if the Add-Ons you used to ingest logs are all CIM 4.x compliant.&lt;/P&gt;&lt;P&gt;When you are sure to have all the data flows of your perimeter, you can go in [Configure &amp;gt; Content &amp;gt; Content Management ] and enable the Correlation Searches that you can use with your data flows.&lt;/P&gt;&lt;P&gt;I hint to make a propedeutic analysis on the Correlation Searches that it's possible to enable with your data; you can do this manually or using the Splunk Security Essentials App (&lt;A href="https://splunkbase.splunk.com/app/3435)" target="_blank"&gt;https://splunkbase.splunk.com/app/3435)&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;I hint to search in the YouTube Splunk Channel some videos that describe hot to install and configure ES.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 10:44:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/642518#M109501</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-05-08T10:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: notable index empty</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/642523#M109506</link>
      <description>&lt;P&gt;This didn't help&lt;/P&gt;&lt;P&gt;Can you give me a video to configure ES?&lt;/P&gt;&lt;P&gt;And why I didn't have inputs.conf?&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 08 May 2023 11:37:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/642523#M109506</guid>
      <dc:creator>NeedNotToKnow</dc:creator>
      <dc:date>2023-05-08T11:37:54Z</dc:date>
    </item>
    <item>
      <title>Re: notable index empty</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/642527#M109507</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/256524"&gt;@NeedNotToKnow&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you don't have inputs.conf because this file is usually on the forwarders that ingest data flows, not on the ES server.&lt;/P&gt;&lt;P&gt;About ES configuring, it isn't so immediate, and I hint to follow a training, otherwise it will very hard!&lt;/P&gt;&lt;P&gt;Anyway, here you can find some documentatin and tutorials:&lt;/P&gt;&lt;P&gt;&lt;A href="https://lantern.splunk.com/Security/Getting_Started/Configuring_and_optimizing_Enterprise_Security" target="_blank"&gt;https://lantern.splunk.com/Security/Getting_Started/Configuring_and_optimizing_Enterprise_Security&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=YMtJjoVk4q0" target="_blank"&gt;https://www.youtube.com/watch?v=YMtJjoVk4q0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=IA2QwdpCm74" target="_blank"&gt;https://www.youtube.com/watch?v=IA2QwdpCm74&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=QdM6JvnYu7g" target="_blank"&gt;https://www.youtube.com/watch?v=QdM6JvnYu7g&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.youtube.com/results?search_query=splunk+enterprise+security" target="_blank"&gt;https://www.youtube.com/results?search_query=splunk+enterprise+security&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 12:09:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/642527#M109507</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-05-08T12:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: notable index empty</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/642534#M109510</link>
      <description>&lt;P&gt;&lt;STRONG&gt;I can’t solve the problem&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;index = notable &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;is empty..&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 13:41:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/642534#M109510</guid>
      <dc:creator>NeedNotToKnow</dc:creator>
      <dc:date>2023-05-08T13:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: notable index empty</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/642538#M109512</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/256524"&gt;@NeedNotToKnow&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;check if you have events in Data Models and if you activated some Correlation Search.&lt;/P&gt;&lt;P&gt;Notable index receive events from the CSs, if you don't enable them and they don't trigger alerts, you'll not have notables.&lt;/P&gt;&lt;P&gt;I cannot hint a CS to start because they depends on the data you have.&lt;/P&gt;&lt;P&gt;As I said, install the Security Essentials App to see which CS are possible to enable.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 13:53:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/642538#M109512</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-05-08T13:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: notable index empty</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/643015#M109586</link>
      <description>&lt;P&gt;Sorry I bothered you many times&lt;/P&gt;&lt;P&gt;Notable get its events from correlation searches ok?&lt;/P&gt;&lt;P&gt;But when I install SPLUNK ES there are many prebuilt CSs&lt;/P&gt;&lt;P&gt;So my task just go and enable them, right?&lt;/P&gt;&lt;P&gt;But these correlation searches run on what index?&lt;/P&gt;&lt;P&gt;For example, if I have two indexes firewall-1 &amp;amp; firewall-2&lt;/P&gt;&lt;P&gt;Is it by default will run these CSs on both of indexes?&lt;/P&gt;&lt;P&gt;Or should I manually edit it? If yes, How?&lt;/P&gt;&lt;P&gt;Did you get me? Sorry for bothering&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 11 May 2023 11:03:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-notable-index-empty/m-p/643015#M109586</guid>
      <dc:creator>NeedNotToKnow</dc:creator>
      <dc:date>2023-05-11T11:03:36Z</dc:date>
    </item>
  </channel>
</rss>

