Splunk Enterprise Security

Enerprise Security posture is empty

m1ster1985
Explorer

I have installed Enterprise Security App. 

I review Security Domain, in particular, Access and Network sections and I see many events coming from my AD, Office 365, and Firewalls.

However, Security Posture dashboards are all empty. 

I have checked permissions and given full access. 

Could you advise what I should check to fix it?

m1ster1985_0-1632126882373.png

 

Labels (2)
0 Karma
1 Solution

ro_mc
Path Finder

You can also check index=notable.

Notable events are typically generated as an Adaptive Response Action for a correlation search.

You can see this from the Enterprise Security menu bar under Configure -> Content -> Content Management. Correlation searches must be enabled and search conditions met before notable events are generated and become visible from the Security Posture and Incident Review dashboards.

You can use existing correlation searches, use the Splunk ES Content Update (ESCU) app from Splunkbase at https://splunkbase.splunk.com/app/3449/, or generate your own searches using the guidance at https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Correlationsearchoverview.

You can also edit the Security Posture dashboard to display other key indicators, but the default ones cover the main security domains and frameworks used by Enterprise Security.

 

View solution in original post

0 Karma

ro_mc
Path Finder

You can also check index=notable.

Notable events are typically generated as an Adaptive Response Action for a correlation search.

You can see this from the Enterprise Security menu bar under Configure -> Content -> Content Management. Correlation searches must be enabled and search conditions met before notable events are generated and become visible from the Security Posture and Incident Review dashboards.

You can use existing correlation searches, use the Splunk ES Content Update (ESCU) app from Splunkbase at https://splunkbase.splunk.com/app/3449/, or generate your own searches using the guidance at https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Correlationsearchoverview.

You can also edit the Security Posture dashboard to display other key indicators, but the default ones cover the main security domains and frameworks used by Enterprise Security.

 

0 Karma

m1ster1985
Explorer

Thank you very much.

I enabled objects in the Content Management and Security Posture instantly filled with different events. 

 

Azeemering
Builder

Did you really check though? The Security Posture dashboard is 100% driven by notables.

Did you check if there are any notables generated?

If you go the the Incident Review dashboard. Do you have any notables there?

Do you get any results when you run the underlying spl queries? ;

| `es_notable_events`

or without macro and even more simple:

| inputlookup es_notable_events

m1ster1985
Explorer

Thank you for the reply. 

The Incident Review dashboard is also empty.

m1ster1985_1-1632134372637.png

I have executed a request and nothing empty result. 

m1ster1985_0-1632134290030.png

But when I review events using Security Domains, I see a lot of events.

For instance, Access Centre.

m1ster1985_2-1632134437542.png

Very strange, I have no idea why this is happening in this way. 

 

 

0 Karma

Azeemering
Builder

Why would it be strange? No notables means no data in the Security Posture dashboard....

Next step for you would be to figure out why you do not have any notables.
Create some test notables.

You can create them this way:

makeresults | eval dest="splunkftw" | sendalert notable

I'm  more worried about the lack of ES knowledge and the task that you got to install and configure ES...

Check this:

https://dev.splunk.com/enterprise/docs/devtools/enterprisesecurity/notableeventsplunkes/

m1ster1985
Explorer

Thank you very much.

You are right, I do not have appropriate knowledge in ES.  😞

Hope, I will fix it in the near future. 

After enabling objects in Content Management, I started receiving notable events. 

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...