Splunk Enterprise Security

Data Inventory Introspection not completing in 3.0.0

PCT80000
Explorer

We have upgraded the app to 3.0.0, but now we cant get the Data Inventory Introspection to complete.

In the previous version under the beta tab, there was an additional button to the right of the "play\pause" button. You were also able to expand the status window and manually correct individual searches.

The result is that we cant use the MITRE ATT&CK framework view any more. Nothing is being shown as active content.

peter_krammer
Communicator

I also had problems with the Data inventory after an update.
I found that the Data in my kv store lookup "data_inventory_products_lookup" was likely outdated from a previous version.
The Addon ships with newer data in SSE-default-data-inventory-products.csv but on update was not loaded into the KV store.

So my issue was fixed by:

| inputlookup SSE-default-data-inventory-products.csv
| outputlookup data_inventory_products_lookup
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...