All Apps and Add-ons

Threat Activity dashboard not populating data from _intel lookups

Path Finder

I have the local_ip_intel and the rest of the local__intel lookups with data. But the Threat Activity dashboard in ES isn't populating for some reason. I have the time field in those lookups as well. Have someone seen the same in their Splunk. Any help is appreciated.


0 Karma


Hi Sanjai676,

check your events that they contains all needed tags and CIM fields otherwise the Thread Gen saved searches will not match.

Hope this helps ...

cheers, MuS

0 Karma
*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!


Or Learn More in Our Blog >>