Splunk Enterprise Security

Data Inventory Introspection not completing in 3.0.0

PCT80000
Explorer

We have upgraded the app to 3.0.0, but now we cant get the Data Inventory Introspection to complete.

In the previous version under the beta tab, there was an additional button to the right of the "play\pause" button. You were also able to expand the status window and manually correct individual searches.

The result is that we cant use the MITRE ATT&CK framework view any more. Nothing is being shown as active content.

peter_krammer
Communicator

I also had problems with the Data inventory after an update.
I found that the Data in my kv store lookup "data_inventory_products_lookup" was likely outdated from a previous version.
The Addon ships with newer data in SSE-default-data-inventory-products.csv but on update was not loaded into the KV store.

So my issue was fixed by:

| inputlookup SSE-default-data-inventory-products.csv
| outputlookup data_inventory_products_lookup
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...