<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk ESS index does not have any data in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ESS-index-does-not-have-any-data/m-p/392532#M4260</link>
    <description>&lt;P&gt;Many indexes are populated only after correlation searches are enabled. Enable the correlation searches that make sense for your security use cases, and you'll start to see data in those related indexes, such as the notable index or the threat_activity index. &lt;/P&gt;</description>
    <pubDate>Tue, 13 Nov 2018 19:36:30 GMT</pubDate>
    <dc:creator>smoir_splunk</dc:creator>
    <dc:date>2018-11-13T19:36:30Z</dc:date>
    <item>
      <title>Splunk ESS index does not have any data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ESS-index-does-not-have-any-data/m-p/392531#M4259</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I am new to splunk. I have installed splunk ESS(5.2) on search head. Splunk environment has one search head and three search peers(indexers). After installing the ESS on search head, I am not able to see any data for the indexes created from ESS like whois, threat_activity. Am I missing anything? Do I require any special configuration on search peers or heavy forwarders?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 19:04:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ESS-index-does-not-have-any-data/m-p/392531#M4259</guid>
      <dc:creator>graju89</dc:creator>
      <dc:date>2018-11-13T19:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ESS index does not have any data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ESS-index-does-not-have-any-data/m-p/392532#M4260</link>
      <description>&lt;P&gt;Many indexes are populated only after correlation searches are enabled. Enable the correlation searches that make sense for your security use cases, and you'll start to see data in those related indexes, such as the notable index or the threat_activity index. &lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 19:36:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ESS-index-does-not-have-any-data/m-p/392532#M4260</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2018-11-13T19:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ESS index does not have any data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ESS-index-does-not-have-any-data/m-p/392533#M4261</link>
      <description>&lt;P&gt;Correlation search is enabled already. Do I need to install any add-ons on the search peers?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 19:41:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ESS-index-does-not-have-any-data/m-p/392533#M4261</guid>
      <dc:creator>graju89</dc:creator>
      <dc:date>2018-11-13T19:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ESS index does not have any data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ESS-index-does-not-have-any-data/m-p/392534#M4262</link>
      <description>&lt;P&gt;ES is made up of add-ons, and if those are not present on the search peers then yes, you will need to distribute them accordingly. These steps are documented: &lt;A href="https://docs.splunk.com/Documentation/ES/5.2.0/Install/InstallTechnologyAdd-ons"&gt;https://docs.splunk.com/Documentation/ES/5.2.0/Install/InstallTechnologyAdd-ons&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 19:43:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ESS-index-does-not-have-any-data/m-p/392534#M4262</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2018-11-13T19:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ESS index does not have any data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ESS-index-does-not-have-any-data/m-p/392535#M4263</link>
      <description>&lt;P&gt;Ok. I saw the link already. I will update once I am done.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 19:48:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ESS-index-does-not-have-any-data/m-p/392535#M4263</guid>
      <dc:creator>graju89</dc:creator>
      <dc:date>2018-11-13T19:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ESS index does not have any data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ESS-index-does-not-have-any-data/m-p/392536#M4264</link>
      <description>&lt;P&gt;@smoir_splunk I installed the add-ons but still no luck.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2018 21:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ESS-index-does-not-have-any-data/m-p/392536#M4264</guid>
      <dc:creator>graju89</dc:creator>
      <dc:date>2018-11-13T21:04:25Z</dc:date>
    </item>
  </channel>
</rss>

