<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunk cloud es notable index empty in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/splunk-cloud-es-notable-index-empty/m-p/444932#M6053</link>
    <description>&lt;P&gt;Hello Splunkers&lt;BR /&gt;
we have splunk managed cloud ES and i have enabled all correlation searches as per doc the way we do on Prem ES.&lt;BR /&gt;
Nothing showing ES posture dashboards and notable events are empty no data under notable index&lt;BR /&gt;
we mapped data models and we validated data with data model fields every thing is there &lt;BR /&gt;
but ES and notable index is empty BW this is splunk managed cloud product &lt;/P&gt;</description>
    <pubDate>Wed, 01 May 2019 23:27:36 GMT</pubDate>
    <dc:creator>Splunk_rocks</dc:creator>
    <dc:date>2019-05-01T23:27:36Z</dc:date>
    <item>
      <title>splunk cloud es notable index empty</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/splunk-cloud-es-notable-index-empty/m-p/444932#M6053</link>
      <description>&lt;P&gt;Hello Splunkers&lt;BR /&gt;
we have splunk managed cloud ES and i have enabled all correlation searches as per doc the way we do on Prem ES.&lt;BR /&gt;
Nothing showing ES posture dashboards and notable events are empty no data under notable index&lt;BR /&gt;
we mapped data models and we validated data with data model fields every thing is there &lt;BR /&gt;
but ES and notable index is empty BW this is splunk managed cloud product &lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 23:27:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/splunk-cloud-es-notable-index-empty/m-p/444932#M6053</guid>
      <dc:creator>Splunk_rocks</dc:creator>
      <dc:date>2019-05-01T23:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: splunk cloud es notable index empty</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/splunk-cloud-es-notable-index-empty/m-p/444933#M6054</link>
      <description>&lt;P&gt;There are many steps for setting up ES that you should do before enabling correlation searches.  On top of that, enabling &lt;STRONG&gt;ALL&lt;/STRONG&gt; of them is an absolutely horrible idea and nobody should ever do that.  Generally ES is sold with PS and your PS team should know better than that and should have done all the setup.  What setup did you do and what documentation did you/they follow for setup?&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2019 01:15:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/splunk-cloud-es-notable-index-empty/m-p/444933#M6054</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-05-02T01:15:41Z</dc:date>
    </item>
  </channel>
</rss>

