I have the local_ip_intel and the rest of the local__intel lookups with data. But the Threat Activity dashboard in ES isn't populating for some reason. I have the time field in those lookups as well. Have someone seen the same in their Splunk. Any help is appreciated.
Thanks.
Hi Sanjai676,
check your events that they contains all needed tags and CIM fields otherwise the Thread Gen
saved searches will not match.
Hope this helps ...
cheers, MuS