All Apps and Add-ons

Why does every search in the RWI - Executive Dashboard app reference data models?

ChadLangUAB
Path Finder

The Splunkbase page for the RWI app states: "There are no major considerations for installing Remote Work Insights - simply follow your usual Splunk App Deployment procedure."

I find this to be very misleading because if you do not have fully populated data models this app will do literally nothing, even if you point the macros to the correct indexes.

Please be transparent if you want people to install & use your app. Advice is welcomed, perhaps I'm missing a relevant workaround.

https://splunkbase.splunk.com/app/4952/#/details

sirpatrick
Explorer

I guess it requires no major consideration so long as you are running the common information model add-on which creates the data models.

There may be more pieces to the puzzle but the network_sessions and authentication data model are both created from within the CIM add-on (link below). I believe this is a heavy hitter so if your Splunk instance is already hitting performance limits during peak usage you may wish to have a conversation before loading this add-on.

https://splunkbase.splunk.com/app/1621/

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...