<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enerprise Security posture is empty in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567790#M10315</link>
    <description>&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;You are right, I do not have appropriate knowledge in ES.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hope, I will fix it in the near future.&amp;nbsp;&lt;/P&gt;&lt;P&gt;After enabling objects in Content Management, I started receiving notable events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Sep 2021 07:45:54 GMT</pubDate>
    <dc:creator>m1ster1985</dc:creator>
    <dc:date>2021-09-21T07:45:54Z</dc:date>
    <item>
      <title>Enerprise Security posture is empty</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567578#M10303</link>
      <description>&lt;P&gt;I have installed Enterprise Security App.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I review Security Domain, in particular, Access and Network sections and I see many events coming from my AD, Office 365, and Firewalls.&lt;/P&gt;&lt;P&gt;However,&amp;nbsp;Security Posture dashboards are all empty.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked permissions and given full access.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you advise what I should check to fix it?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="m1ster1985_0-1632126882373.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16055i9A55A5FAB6D92816/image-size/medium?v=v2&amp;amp;px=400" role="button" title="m1ster1985_0-1632126882373.png" alt="m1ster1985_0-1632126882373.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 08:34:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567578#M10303</guid>
      <dc:creator>m1ster1985</dc:creator>
      <dc:date>2021-09-20T08:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Enerprise Security posture is empty</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567628#M10308</link>
      <description>&lt;P&gt;Did you really check though? The Security Posture dashboard is 100% driven by&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;notables&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Did you check if there are any notables generated?&lt;/P&gt;&lt;P&gt;If you go the the&amp;nbsp;&lt;STRONG&gt;Incident Review&amp;nbsp;&lt;/STRONG&gt;dashboard. Do you have any notables there?&lt;BR /&gt;&lt;BR /&gt;Do you get any results when you run the underlying spl queries? ;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;| `es_notable_events`&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;or without macro and even more simple:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;| inputlookup es_notable_events&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 10:06:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567628#M10308</guid>
      <dc:creator>Azeemering</dc:creator>
      <dc:date>2021-09-20T10:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: Enerprise Security posture is empty</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567639#M10310</link>
      <description>&lt;P&gt;Thank you for the reply.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Incident Review&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN&gt;dashboard is also empty.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="m1ster1985_1-1632134372637.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16060iAF47426A54239F30/image-size/medium?v=v2&amp;amp;px=400" role="button" title="m1ster1985_1-1632134372637.png" alt="m1ster1985_1-1632134372637.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have executed a request and nothing empty result.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="m1ster1985_0-1632134290030.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16059i241DCC0E8184CAD3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="m1ster1985_0-1632134290030.png" alt="m1ster1985_0-1632134290030.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But when I review events using &lt;STRONG&gt;Security Domains, &lt;/STRONG&gt;I see a lot of events.&lt;/P&gt;&lt;P&gt;For instance, Access Centre.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="m1ster1985_2-1632134437542.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16061i48E9FAAAF3B67D07/image-size/medium?v=v2&amp;amp;px=400" role="button" title="m1ster1985_2-1632134437542.png" alt="m1ster1985_2-1632134437542.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Very strange, I have no idea why this is happening in this way.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 10:42:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567639#M10310</guid>
      <dc:creator>m1ster1985</dc:creator>
      <dc:date>2021-09-20T10:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: Enerprise Security posture is empty</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567643#M10311</link>
      <description>&lt;P&gt;Why would it be strange? No notables means no data in the Security Posture dashboard....&lt;/P&gt;&lt;P&gt;Next step for you would be to figure out why you do not have any notables.&lt;BR /&gt;Create some test notables.&lt;/P&gt;&lt;P&gt;You can create them this way:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;makeresults | eval dest="splunkftw" | sendalert notable&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I'm&amp;nbsp; more worried about the lack of ES knowledge and the task that you got to install and configure ES...&lt;/P&gt;&lt;P&gt;Check this:&lt;/P&gt;&lt;P&gt;&lt;A href="https://dev.splunk.com/enterprise/docs/devtools/enterprisesecurity/notableeventsplunkes/" target="_blank"&gt;https://dev.splunk.com/enterprise/docs/devtools/enterprisesecurity/notableeventsplunkes/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 10:50:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567643#M10311</guid>
      <dc:creator>Azeemering</dc:creator>
      <dc:date>2021-09-20T10:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security posture is empty</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567668#M10312</link>
      <description>&lt;P&gt;You can also check &lt;EM&gt;&lt;STRONG&gt;index=notable&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Notable events&lt;/STRONG&gt; are typically generated as an &lt;STRONG&gt;Adaptive Response Action&lt;/STRONG&gt; for a &lt;STRONG&gt;correlation search&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;You can see this from the Enterprise Security menu bar under&amp;nbsp;Configure -&amp;gt; Content -&amp;gt; Content Management. Correlation searches must be enabled and search conditions met before notable events are generated and become visible from the Security Posture and Incident Review dashboards.&lt;/P&gt;&lt;P&gt;You can use existing correlation searches, use the Splunk ES Content Update (ESCU) app from Splunkbase at &lt;A href="https://splunkbase.splunk.com/app/3449/" target="_blank"&gt;https://splunkbase.splunk.com/app/3449/&lt;/A&gt;, or generate your own searches using the guidance at &lt;A href="https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Correlationsearchoverview" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Correlationsearchoverview&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;You can also &lt;STRONG&gt;edit&lt;/STRONG&gt; the Security Posture dashboard to display other key indicators, but the default ones cover the main security domains and frameworks used by Enterprise Security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 13:38:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567668#M10312</guid>
      <dc:creator>ro_mc</dc:creator>
      <dc:date>2021-09-20T13:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security posture is empty</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567789#M10314</link>
      <description>&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;I enabled objects in the Content Management and Security Posture&amp;nbsp;instantly filled with different events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 07:39:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567789#M10314</guid>
      <dc:creator>m1ster1985</dc:creator>
      <dc:date>2021-09-21T07:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Enerprise Security posture is empty</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567790#M10315</link>
      <description>&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;You are right, I do not have appropriate knowledge in ES.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Hope, I will fix it in the near future.&amp;nbsp;&lt;/P&gt;&lt;P&gt;After enabling objects in Content Management, I started receiving notable events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Sep 2021 07:45:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enerprise-Security-posture-is-empty/m-p/567790#M10315</guid>
      <dc:creator>m1ster1985</dc:creator>
      <dc:date>2021-09-21T07:45:54Z</dc:date>
    </item>
  </channel>
</rss>

