Splunk Enterprise Security

Need help with threat activity dashboards in ESS

Path Finder


My Threat Activity dashboards returning zero result found message on every dashboard.

I turned on data model for threat and threat downloads for all locals

When ever I am searching for ipintel and serviceintel, then I am getting the result but all dashboards are empty.

Please do help me.

Any help would be appreciated. alt text

0 Karma


Hi satyaallaparthi, please check this troubleshoot guide, maybe it can help you to find your issue.


0 Karma