All Apps and Add-ons

Bit9 Security Platform: Why am I not getting any "Trust" information in dashboard panels?

brooklynotss
Path Finder

Followed the install instructions from here: https://splunkbase.splunk.com/app/1790/#/documentation
Everything but Trust panels seems to be working as expected, meaning data is flowing in, all other dashboard panels display information, but any dashboard panel that references Trust scores is showing no data... Any ideas?

Love the pivot! well done.

0 Karma
1 Solution

aweitzman
Motivator

Have you activated the Bit9 Software Reputation Service? You will need this activated in order to receive trust scores.

What results do you get when you run this search in Splunk?

eventtype=bit9_fileCatalog | top 0 TrustValue

View solution in original post

0 Karma

aweitzman
Motivator

Have you activated the Bit9 Software Reputation Service? You will need this activated in order to receive trust scores.

What results do you get when you run this search in Splunk?

eventtype=bit9_fileCatalog | top 0 TrustValue
0 Karma

brooklynotss
Path Finder

ok sorry - it's working now. I made no changes. past two days nothing was showing up for those Trust panels.

0 Karma

mreynov_splunk
Splunk Employee
Splunk Employee

There is not enough information here to answer your question. Install instructions for what? Trust scores where - ES? If so, how was your ES configured? Which data sources do you have?

0 Karma

brooklynotss
Path Finder

Sorry I was relying too much on the tags. This has only to do with the bit9 app. Nothing about ES. Bit9 is the answer to all of your questions.

0 Karma

mreynov_splunk
Splunk Employee
Splunk Employee

which bit9 app? link, please.

0 Karma

brooklynotss
Path Finder

pretty sure there is only one called Bit9 Security Platform: https://splunkbase.splunk.com/app/1790/#/documentation

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...