<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk ES Installation and Configuration dashboard error. in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Installation-and-Configuration-dashboard-error/m-p/419943#M5157</link>
    <description>&lt;P&gt;What do you mean by &lt;CODE&gt;installing ES apps&lt;/CODE&gt;?  Do you mean &lt;CODE&gt;installing ES&lt;/CODE&gt;?  Do you mean installing &lt;CODE&gt;TAs&lt;/CODE&gt;?  Who setup you ES; did you do it yourself or did you get PS?&lt;/P&gt;</description>
    <pubDate>Sun, 03 Mar 2019 04:56:49 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2019-03-03T04:56:49Z</dc:date>
    <item>
      <title>Splunk ES Installation and Configuration dashboard error.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Installation-and-Configuration-dashboard-error/m-p/419940#M5154</link>
      <description>&lt;P&gt;I first time installing ES apps on Splunk Enterprise 7.2.1 with ES version 5.2.0.&lt;/P&gt;

&lt;P&gt;Splunk Environment:-&lt;BR /&gt;
1 SH standalone&lt;BR /&gt;
3 Indexer in Cluster mode&lt;/P&gt;

&lt;P&gt;Installation of ES apps&lt;BR /&gt;
1.Installation of ES done successfully ,But not able to see any data over ES dashboard.&lt;BR /&gt;
2.All ES data-models are accelerated.&lt;BR /&gt;
3.No event is in notable event&lt;/P&gt;</description>
      <pubDate>Sat, 02 Mar 2019 21:54:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Installation-and-Configuration-dashboard-error/m-p/419940#M5154</guid>
      <dc:creator>rafeeqsid25</dc:creator>
      <dc:date>2019-03-02T21:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES Installation and Configuration dashboard error.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Installation-and-Configuration-dashboard-error/m-p/419941#M5155</link>
      <description>&lt;P&gt;What ES dashboard? The security posture? &lt;/P&gt;

&lt;P&gt;Have you enabled or created correlation searches that have alert actions as create notable events? If not, then you can't expect dashboards based on notables if they don't exist yet.&lt;/P&gt;

&lt;P&gt;Let us know&lt;/P&gt;</description>
      <pubDate>Sat, 02 Mar 2019 22:18:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Installation-and-Configuration-dashboard-error/m-p/419941#M5155</guid>
      <dc:creator>tiagofbmm</dc:creator>
      <dc:date>2019-03-02T22:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES Installation and Configuration dashboard error.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Installation-and-Configuration-dashboard-error/m-p/419942#M5156</link>
      <description>&lt;P&gt;Hey @rafeeqsid25,&lt;/P&gt;

&lt;P&gt;I'm assuming by your saying there's no data on the dashboard, there's no data on any of them? Your "all ES datamodels are accelerated" comment kind of tips me off, as it's not too common to see an environment where they all are. &lt;/P&gt;

&lt;P&gt;There's kind of a lot to go through here, and I don't know how familiar you are with Splunk or its mechanisms, so I'll start at the baseline.&lt;/P&gt;

&lt;P&gt;Do you know if your data is CIM-compliant? You can get an overview of CIM, the Common Information Model, here: &lt;A href="https://docs.splunk.com/Documentation/CIM/4.12.0/User/Overview"&gt;https://docs.splunk.com/Documentation/CIM/4.12.0/User/Overview&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;ES dashboards are populated by searches based - mostly - on the summaries created by accelerated data models. But the acceleration of that data is dependent on the data being normalized to that Common Information Model.&lt;/P&gt;

&lt;P&gt;Try this. Datamodel summaries - what model accelerations create - are generated by underlying searches. Those searches look something like this:&lt;/P&gt;

&lt;P&gt;`relevant_indexes` tag=relevant&lt;/P&gt;

&lt;P&gt;Take any of those models, and run their searches ad-hoc. Do you get results? If not, they're probably not CIM compliant, or you just don't have the data applicable to that model. Or both.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Mar 2019 04:29:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Installation-and-Configuration-dashboard-error/m-p/419942#M5156</guid>
      <dc:creator>johnvr</dc:creator>
      <dc:date>2019-03-03T04:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES Installation and Configuration dashboard error.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Installation-and-Configuration-dashboard-error/m-p/419943#M5157</link>
      <description>&lt;P&gt;What do you mean by &lt;CODE&gt;installing ES apps&lt;/CODE&gt;?  Do you mean &lt;CODE&gt;installing ES&lt;/CODE&gt;?  Do you mean installing &lt;CODE&gt;TAs&lt;/CODE&gt;?  Who setup you ES; did you do it yourself or did you get PS?&lt;/P&gt;</description>
      <pubDate>Sun, 03 Mar 2019 04:56:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Installation-and-Configuration-dashboard-error/m-p/419943#M5157</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-03-03T04:56:49Z</dc:date>
    </item>
  </channel>
</rss>

