<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Strange issue with missing menu in Enterprise Security in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417330#M5053</link>
    <description>&lt;P&gt;I'm hoping someone can assist me with this strange issue.  For some reason my menu bar for enterprise security is gone when on the "Home" choice, i.e. it only shows the "search" choice.  However, if I click on Incident Review, the bar shows up and everything else renders properly, with the exception that "Investigations" has the same issue.  I've compared everything in my SplunkEnterpriseSecurity app directory with the installation tar, and have poked around in the local dir to see if anything has changed.  I can even look at the source code on the page and I see the menu choices in the javascript.  They just don't render.  Any ideas??&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5604i2AE16AFE061A0C08/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5605i3B23C97D7E12B599/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Aug 2018 13:53:11 GMT</pubDate>
    <dc:creator>tommoore</dc:creator>
    <dc:date>2018-08-21T13:53:11Z</dc:date>
    <item>
      <title>Strange issue with missing menu in Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417330#M5053</link>
      <description>&lt;P&gt;I'm hoping someone can assist me with this strange issue.  For some reason my menu bar for enterprise security is gone when on the "Home" choice, i.e. it only shows the "search" choice.  However, if I click on Incident Review, the bar shows up and everything else renders properly, with the exception that "Investigations" has the same issue.  I've compared everything in my SplunkEnterpriseSecurity app directory with the installation tar, and have poked around in the local dir to see if anything has changed.  I can even look at the source code on the page and I see the menu choices in the javascript.  They just don't render.  Any ideas??&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5604i2AE16AFE061A0C08/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5605i3B23C97D7E12B599/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 13:53:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417330#M5053</guid>
      <dc:creator>tommoore</dc:creator>
      <dc:date>2018-08-21T13:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: Strange issue with missing menu in Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417331#M5054</link>
      <description>&lt;P&gt;Look and see if you have a nav.xml in a local directory that might be getting precedence. &lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 14:32:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417331#M5054</guid>
      <dc:creator>sjohnson_splunk</dc:creator>
      <dc:date>2018-12-20T14:32:10Z</dc:date>
    </item>
    <item>
      <title>Re: Strange issue with missing menu in Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417332#M5055</link>
      <description>&lt;P&gt;Thanks for commenting on this, I had forgotten I had opened it.&lt;/P&gt;

&lt;P&gt;Turns out the TA for Okta was somehow affecting the dashboard.  I removed it and things returned to normal. &lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 14:41:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417332#M5055</guid>
      <dc:creator>tommoore</dc:creator>
      <dc:date>2018-12-20T14:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: Strange issue with missing menu in Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417333#M5056</link>
      <description>&lt;P&gt;Turns out the TA for Okta was somehow affecting the dashboard. I removed it and things returned to normal. &lt;/P&gt;</description>
      <pubDate>Thu, 20 Dec 2018 14:41:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417333#M5056</guid>
      <dc:creator>tommoore</dc:creator>
      <dc:date>2018-12-20T14:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Strange issue with missing menu in Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417334#M5057</link>
      <description>&lt;P&gt;So, the actual problem was that the Okta TA was automatically getting "included" into the ES app, so the nav and views defined in that TA were 'a part of' the ES app. See &lt;A href="https://docs.splunk.com/Documentation/ES/5.2.2/Install/ImportCustomApps" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/5.2.2/Install/ImportCustomApps&lt;/A&gt; for information on this feature of ES. By default, any app that starts with "TA-" (and others) is automatically "imported" into the ES app. Since the Okta add-on starts with "TA-" (the name is "TA-Okta_Identity_Cloud_for_Splunk"), it was getting imported and visible in ES, causing the nav issues (and other pages to show up).&lt;/P&gt;

&lt;P&gt;To fix:&lt;BR /&gt;
1. In the ES app, navigate to "Configure | General | App Imports Update".&lt;BR /&gt;
2. Click on the "update_es" item to edit it.&lt;BR /&gt;
3. Add "|TA-Okta_Identity_Cloud_for_Splunk" to the "Application Exclusion Regular Expression" field.&lt;BR /&gt;
4. Save your changes.&lt;BR /&gt;
5. Restart Splunk.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:18:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417334#M5057</guid>
      <dc:creator>kcepull_splunk</dc:creator>
      <dc:date>2020-09-29T23:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Strange issue with missing menu in Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417335#M5058</link>
      <description>&lt;P&gt;Ran into the same issue with one of my customers.  We found that removing the file "custom.xml" located in default/data/ui/nav in the Okta add-on fixed the issue, and still let us use the search-time parsing in ES for Okta events.  I'm not sure why custom.xml is there, since it is identical to default.xml in the same directory.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 17:13:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417335#M5058</guid>
      <dc:creator>brian_rampley</dc:creator>
      <dc:date>2019-04-24T17:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Strange issue with missing menu in Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417336#M5059</link>
      <description>&lt;P&gt;This worked for me as well.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 03:45:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Strange-issue-with-missing-menu-in-Enterprise-Security/m-p/417336#M5059</guid>
      <dc:creator>splunk_rohitsha</dc:creator>
      <dc:date>2019-11-14T03:45:47Z</dc:date>
    </item>
  </channel>
</rss>

