Splunk Enterprise Security

Data Inventory Introspection not completing in 3.0.0

PCT80000
Explorer

We have upgraded the app to 3.0.0, but now we cant get the Data Inventory Introspection to complete.

In the previous version under the beta tab, there was an additional button to the right of the "play\pause" button. You were also able to expand the status window and manually correct individual searches.

The result is that we cant use the MITRE ATT&CK framework view any more. Nothing is being shown as active content.

peter_krammer
Communicator

I also had problems with the Data inventory after an update.
I found that the Data in my kv store lookup "data_inventory_products_lookup" was likely outdated from a previous version.
The Addon ships with newer data in SSE-default-data-inventory-products.csv but on update was not loaded into the KV store.

So my issue was fixed by:

| inputlookup SSE-default-data-inventory-products.csv
| outputlookup data_inventory_products_lookup
0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...