Splunk Enterprise Security

Need help with threat activity dashboards in ESS

satyaallaparthi
Communicator

Hello,

My Threat Activity dashboards returning zero result found message on every dashboard.

I turned on data model for threat and threat downloads for all locals

When ever I am searching for ip_intel and service_intel, then I am getting the result but all dashboards are empty.

Please do help me.

Any help would be appreciated. alt text

0 Karma

ivanreis
Builder

Hi satyaallaparthi, please check this troubleshoot guide, maybe it can help you to find your issue.

https://docs.splunk.com/Documentation/ES/5.3.1/Admin/Troubleshootdashboards

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Nested loops in Event Conversion

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...