Splunk Enterprise Security

Data Inventory Introspection not completing in 3.0.0

PCT80000
Explorer

We have upgraded the app to 3.0.0, but now we cant get the Data Inventory Introspection to complete.

In the previous version under the beta tab, there was an additional button to the right of the "play\pause" button. You were also able to expand the status window and manually correct individual searches.

The result is that we cant use the MITRE ATT&CK framework view any more. Nothing is being shown as active content.

peter_krammer
Communicator

I also had problems with the Data inventory after an update.
I found that the Data in my kv store lookup "data_inventory_products_lookup" was likely outdated from a previous version.
The Addon ships with newer data in SSE-default-data-inventory-products.csv but on update was not loaded into the KV store.

So my issue was fixed by:

| inputlookup SSE-default-data-inventory-products.csv
| outputlookup data_inventory_products_lookup
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...