All Apps and Add-ons

Splunk Security Essentials mitre_overview Not Loading Correctly

kprior201_lilly
Path Finder

I just upgraded my Splunk Security Essentials app from 3.1.1 to 3.3.3. I'm running Splunk Enterprise 8.1.4. When I access the Analytics Advisor / MITRE ATT&CK Framework page, the MITRE ATT&CK Matrix just refuses to load. Has anyone encountered this, and do you have any troubleshooting suggestions? matrix.png

Labels (2)
0 Karma

aasabatini
Motivator

Hi @kprior201_lilly 

did you try to check the sources again on the security essentials?

aasabatini_0-1621922103805.pngaasabatini_1-1621922140570.png

 

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

kprior201_lilly
Path Finder

I just poked around in that screen, but it doesn't seem to be what I'm looking for. Previously, the MITRE matrix loaded just fine; I have content enabled that should reflect here. The rest of the page loads as well; it's just the one matrix that isn't working. 

0 Karma

aasabatini
Motivator

Hi @kprior201_lilly 

what version of security essentials do you have installed?

Can you share a screen of mitre matrix to check the error?

Regards

Alessandro

“The answer is out there, Neo, and it’s looking for you, and it will find you if you want it to.”
0 Karma

kprior201_lilly
Path Finder

It's version 3.3.3; the screenshot is attached to the original post. It doesn't give an error at all, it just doesn't display the matrix. When I look at the Job Inspector, there aren't any errors, either. 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...