Splunk Enterprise Security

Enterprise Security malware dashboard not populating

montydo
Explorer

I'm trying to get the Splunk Enterprise Security Malware dashboards to populate:

I'm ingesting data from symantec using the Splunk_TA_symantec-ep V3.0.1 TA which is indexing my data correctly from the dump files on the symantec management server. These are being forwarded by UF to an indexer (also with the app installed) and finally to the search head (also with the app installed)

In the Enterprise Security app I have checked that the data model receives data following this YT Demystifying the CIM I can run Pivot searches and confirm that the data is being correctly picked up with associated event fields as descibed in the video and evidenced by the screenshot below.

PivotTableExample1

I can confirm the Data Model can access the index storing the symantec data via the CIM-configuration, and I have accelerated the data model. But still no population of the dashboards.

Any help would be greatly appreciated.

Labels (2)
0 Karma

montydo
Explorer

I may have solved my own question here, but did the endpoint data models also need to be enabled?

I think I've fixed it!

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...