- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Enterprise Security: Dashboards not loading data

RK_sp1unk
New Member
09-24-2019
08:36 AM
We have a indexer , heavy forwarder, 2 search head , 1 deployment server .
The splunk enterprise Search head dashboards are pulling data and is looking good.
The other search head for enterprise security , dashboards are not pulling data.
I checked the data models are there , apps are updated.
Saw an distributed search alert stating "the rest uri https://10.102.102.212:8089 is not connecting as peer status is 2", not sure is it because of that.
However need urgent help how to get at least default Splunk ES dashboards like security posture,incident review etc to show data.
Please share your thoughts
