All Apps and Add-ons

Unable to find tag security

damode
Motivator

I am getting the error - Unable to find tag security on the below panels on the security posture dashboard.

360 View by Accounts: Event Types over

Search : `infosec-indexes (tag=security OR tag=attack) | eval tag=mvfilter(match(tag, "failure") OR match(tag, "success") OR match(tag, "access") OR match(tag, "add") OR match(tag, "change") OR match(tag, "delete") OR match(tag, "error") OR match(tag, "misconfiguration") OR match(tag, "vulnerability") OR match(tag, "attack") OR match(tag, "lock") OR match(tag, "cleared") OR match(tag, "email")) | stats count, dc(user) by date_hour, tag`

Time 360 View by hosts: Event Types over Time

I checked all the tags and there is no security tag but there are definitely mutiple tags called attack, still the search within the mentioned panels is not working.

Please advise.

igifrin_splunk
Splunk Employee
Splunk Employee

Are you getting a warning message like the one on the screenshot below?

alt text

If that's the case, you should still see correct results on the dashboard panel for the data you have; you just don't have data with tag=security as you pointed out.

This may not be a bad warning to see. For example, it can be an indication that you don't have Windows security logs or you are not using Windows add-on that add the 'security' tag.

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...