<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: When trying to create a dashboard for Risk Analysis In Splunk Enterprise Security, why am I getting the following error: &amp;quot;the search for datamodel 'Risk' failed to parse&amp;quot; in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387694#M4112</link>
    <description>&lt;P&gt;There is version issue splunk enterprise security, Now we are planning to install new version of security App&lt;/P&gt;</description>
    <pubDate>Tue, 16 Oct 2018 09:24:53 GMT</pubDate>
    <dc:creator>sahiltcs</dc:creator>
    <dc:date>2018-10-16T09:24:53Z</dc:date>
    <item>
      <title>When trying to create a dashboard for Risk Analysis In Splunk Enterprise Security, why am I getting the following error: "the search for datamodel 'Risk' failed to parse"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387685#M4103</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have Splunk enterprise security version 6.5.3.1 and am trying to create a dashboard for Risk Analysis. When I click on the Risk Analysis tab, I am not able to see any dashboards and also nothing is showing in the Incident Review tab. &lt;/P&gt;

&lt;P&gt;I am getting the following error: "The search for datamodel 'Risk' failed to parse, cannot get indexes to search" &lt;/P&gt;

&lt;P&gt;Can you please help me figure out why I am getting this error?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sahil &lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 04:34:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387685#M4103</guid>
      <dc:creator>sahiltcs</dc:creator>
      <dc:date>2018-09-21T04:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: When trying to create a dashboard for Risk Analysis In Splunk Enterprise Security, why am I getting the following error: "the search for datamodel 'Risk' failed to parse"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387686#M4104</link>
      <description>&lt;P&gt;It sounds like it either the 'risk' index isn't there or there is no data in the 'risk' index, or there is a permissions issue.&lt;/P&gt;

&lt;P&gt;So, I would look at two things to start with. &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Is there a 'Risk' index, and does it have data? You can also run a search against the 'risk' index.&lt;/LI&gt;
&lt;LI&gt;Go to the Risk Analysis Data Model and hit the drop down for edit, and select 'edit permissions'. I believe it should be set by default to Display for 'All Apps', Everyone = Read, Admin = Write&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Hope this helps&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 12:32:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387686#M4104</guid>
      <dc:creator>joebisesi</dc:creator>
      <dc:date>2018-09-21T12:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: When trying to create a dashboard for Risk Analysis In Splunk Enterprise Security, why am I getting the following error: "the search for datamodel 'Risk' failed to parse"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387687#M4105</link>
      <description>&lt;P&gt;Hi Joebiesi,&lt;/P&gt;

&lt;P&gt;I changed the permissions and run risk index and they have data but still it not works.&lt;/P&gt;

&lt;P&gt;Is there any issue Version Bug in the version ?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Sep 2018 07:14:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387687#M4105</guid>
      <dc:creator>sahiltcs</dc:creator>
      <dc:date>2018-09-25T07:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: When trying to create a dashboard for Risk Analysis In Splunk Enterprise Security, why am I getting the following error: "the search for datamodel 'Risk' failed to parse"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387688#M4106</link>
      <description>&lt;P&gt;Any Update Please Confirm&lt;/P&gt;</description>
      <pubDate>Wed, 26 Sep 2018 10:27:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387688#M4106</guid>
      <dc:creator>sahiltcs</dc:creator>
      <dc:date>2018-09-26T10:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: When trying to create a dashboard for Risk Analysis In Splunk Enterprise Security, why am I getting the following error: "the search for datamodel 'Risk' failed to parse"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387689#M4107</link>
      <description>&lt;P&gt;No version bug that I am aware of.&lt;BR /&gt;
Let me ask a clarifying question. &lt;BR /&gt;
Are you unable to see the dashboard, or is not finding any results?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Oct 2018 12:55:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387689#M4107</guid>
      <dc:creator>joebisesi</dc:creator>
      <dc:date>2018-10-01T12:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: When trying to create a dashboard for Risk Analysis In Splunk Enterprise Security, why am I getting the following error: "the search for datamodel 'Risk' failed to parse"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387690#M4108</link>
      <description>&lt;P&gt;It is not finding any result when I go to Risk analysis TAB Because eventtypes with macros don’t work”. &lt;/P&gt;

&lt;P&gt;Do we need to change anything in configuration file or What action we need to perform?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 04:35:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387690#M4108</guid>
      <dc:creator>sahiltcs</dc:creator>
      <dc:date>2018-10-03T04:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: When trying to create a dashboard for Risk Analysis In Splunk Enterprise Security, why am I getting the following error: "the search for datamodel 'Risk' failed to parse"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387691#M4109</link>
      <description>&lt;P&gt;Are you still getting the original error of 'The search for datamodel 'Risk' failed to parse, cannot get indexes to search' ?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 10:34:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387691#M4109</guid>
      <dc:creator>joebisesi</dc:creator>
      <dc:date>2018-10-03T10:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: When trying to create a dashboard for Risk Analysis In Splunk Enterprise Security, why am I getting the following error: "the search for datamodel 'Risk' failed to parse"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387692#M4110</link>
      <description>&lt;P&gt;Yes I am getting same error, Its version issue I guess , I asked concered team to install new enterprise security app&lt;/P&gt;

&lt;P&gt;Any thoughts ?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Sahil&lt;/P&gt;</description>
      <pubDate>Wed, 03 Oct 2018 11:21:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387692#M4110</guid>
      <dc:creator>sahiltcs</dc:creator>
      <dc:date>2018-10-03T11:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: When trying to create a dashboard for Risk Analysis In Splunk Enterprise Security, why am I getting the following error: "the search for datamodel 'Risk' failed to parse"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387693#M4111</link>
      <description>&lt;P&gt;There is version issue splunk enterprise security, Now we are planning to install new version of security App&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 09:24:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387693#M4111</guid>
      <dc:creator>sahiltcs</dc:creator>
      <dc:date>2018-10-16T09:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: When trying to create a dashboard for Risk Analysis In Splunk Enterprise Security, why am I getting the following error: "the search for datamodel 'Risk' failed to parse"</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387694#M4112</link>
      <description>&lt;P&gt;There is version issue splunk enterprise security, Now we are planning to install new version of security App&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 09:24:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/When-trying-to-create-a-dashboard-for-Risk-Analysis-In-Splunk/m-p/387694#M4112</guid>
      <dc:creator>sahiltcs</dc:creator>
      <dc:date>2018-10-16T09:24:53Z</dc:date>
    </item>
  </channel>
</rss>

