Splunk Enterprise Security

Need help with threat activity dashboards in ESS

satyaallaparthi
Communicator

Hello,

My Threat Activity dashboards returning zero result found message on every dashboard.

I turned on data model for threat and threat downloads for all locals

When ever I am searching for ip_intel and service_intel, then I am getting the result but all dashboards are empty.

Please do help me.

Any help would be appreciated. alt text

0 Karma

ivanreis
Builder

Hi satyaallaparthi, please check this troubleshoot guide, maybe it can help you to find your issue.

https://docs.splunk.com/Documentation/ES/5.3.1/Admin/Troubleshootdashboards

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...