Splunk Enterprise Security

Correlation search not running Enteprise Security App

burakatabay
Path Finder
Hi,
Why splunk correlation searches not running on SplunkEnterpriseSecurity App ? but correlation search run another app for example search and reporting app
ES versiyon 6.2.0 Splunk Version 8.0.4
for example : Substantial Increase In Intrusion Events
I upload screenshoot on event.
1.JPG2.JPG
 

 

Labels (2)
Tags (1)
0 Karma
1 Solution

burakatabay
Path Finder

Thank you for answer.

We found problem in splunk installation phase.

The problem is installation user name is not admin it's anothername.

So App level permission doesn't working. We fix the problem. :+1

 

View solution in original post

0 Karma

anilchaithu
Builder

@burakatabay 

Initial debug is to check app level permissions for this datamodel? Does this datamodel is shared across all the apps?

0 Karma

burakatabay
Path Finder

Thank you for answer.

We found problem in splunk installation phase.

The problem is installation user name is not admin it's anothername.

So App level permission doesn't working. We fix the problem. :+1

 

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...