<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why are most of my Ent. Security Dashboards are blank? How do I open the flood gates of data or events into ES in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-are-most-of-my-Ent-Security-Dashboards-are-blank-How-do-I/m-p/545253#M37444</link>
    <description>&lt;P&gt;Thank u for your message. Yes, most of the environment was set up before I started. There are 30 or so datamodels mapped to apps &amp;amp; few 1000 saved searches. But the dashboards all pretty much say no data available!! Please advise. Also advise on how to best use the data models I have. Thank u&lt;/P&gt;</description>
    <pubDate>Thu, 25 Mar 2021 04:00:36 GMT</pubDate>
    <dc:creator>SamHTexas</dc:creator>
    <dc:date>2021-03-25T04:00:36Z</dc:date>
    <item>
      <title>Why are most of my Ent. Security Dashboards are blank? How do I open the flood gates of data or events into ES</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-are-most-of-my-Ent-Security-Dashboards-are-blank-How-do-I/m-p/545232#M37439</link>
      <description>&lt;P&gt;Why are most of my Ent. Security Dashboards are blank? How do I open the flood gates of data or events into ES. Matter what options I pick or which dashboard, says no result&amp;nbsp; found. We have a large environment, where are the events &amp;amp; all the goods &amp;amp; incidents?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 22:04:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-are-most-of-my-Ent-Security-Dashboards-are-blank-How-do-I/m-p/545232#M37439</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-03-24T22:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why are most of my Ent. Security Dashboards are blank? How do I open the flood gates of data or events into ES</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-are-most-of-my-Ent-Security-Dashboards-are-blank-How-do-I/m-p/545236#M37441</link>
      <description>&lt;P&gt;Many ES dashboards are populated by datamodels.&amp;nbsp; Have you set yours up?&amp;nbsp; Have you enabled correlation searches appropriate for your data?&amp;nbsp; Most importantly, is your data CIM-compliant?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 23:24:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-are-most-of-my-Ent-Security-Dashboards-are-blank-How-do-I/m-p/545236#M37441</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-24T23:24:40Z</dc:date>
    </item>
    <item>
      <title>Re: Why are most of my Ent. Security Dashboards are blank? How do I open the flood gates of data or events into ES</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-are-most-of-my-Ent-Security-Dashboards-are-blank-How-do-I/m-p/545253#M37444</link>
      <description>&lt;P&gt;Thank u for your message. Yes, most of the environment was set up before I started. There are 30 or so datamodels mapped to apps &amp;amp; few 1000 saved searches. But the dashboards all pretty much say no data available!! Please advise. Also advise on how to best use the data models I have. Thank u&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 04:00:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-are-most-of-my-Ent-Security-Dashboards-are-blank-How-do-I/m-p/545253#M37444</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-03-25T04:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why are most of my Ent. Security Dashboards are blank? How do I open the flood gates of data or events into ES</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-are-most-of-my-Ent-Security-Dashboards-are-blank-How-do-I/m-p/545437#M37469</link>
      <description>&lt;P&gt;There is no easy answer for this problem.&amp;nbsp; I suspect data was not onboarded to be CIM-compliant so now it can't be found by the datamodels.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Review an empty dashboard to see what it is trying to find.&amp;nbsp; Verify there is data meeting those requirements (same sourcetype, tags, fields, etc).&amp;nbsp; Add fields, aliases, and tags as necessary for the search to find the data.&amp;nbsp; Avoid modifying the built-in datamodels.&lt;/P&gt;&lt;P&gt;Repeat for each empty panel.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 15:50:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-are-most-of-my-Ent-Security-Dashboards-are-blank-How-do-I/m-p/545437#M37469</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-25T15:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: Why are most of my Ent. Security Dashboards are blank? How do I open the flood gates of data or events into ES</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-are-most-of-my-Ent-Security-Dashboards-are-blank-How-do-I/m-p/545767#M37485</link>
      <description>&lt;P&gt;Great, it is making a lot of sense. So what role do Lookup tables make in this picture?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Mar 2021 18:50:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-are-most-of-my-Ent-Security-Dashboards-are-blank-How-do-I/m-p/545767#M37485</guid>
      <dc:creator>SamHTexas</dc:creator>
      <dc:date>2021-03-28T18:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why are most of my Ent. Security Dashboards are blank? How do I open the flood gates of data or events into ES</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-are-most-of-my-Ent-Security-Dashboards-are-blank-How-do-I/m-p/545770#M37486</link>
      <description>&lt;P&gt;Lookups enrich data.&amp;nbsp; In ES, they add asset and identity information to notable events in addition to whatever custom enrichments your searches may need.&lt;/P&gt;&lt;P&gt;I doubt lookups are a cause of your blank dashboards, however.&amp;nbsp; If the lookups were failing then you'd still see *something* on the dashboard.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Mar 2021 19:42:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-are-most-of-my-Ent-Security-Dashboards-are-blank-How-do-I/m-p/545770#M37486</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-28T19:42:13Z</dc:date>
    </item>
  </channel>
</rss>

