Splunk Enterprise Security

Splunk Enterprise security search head is not pulling logs from firewall, waf,proxy logs, MFA, sandbox, ...network resources but my other search head for apps is getting all data

RK_sp1unk
New Member

Splunk Enterprise security search head is not pulling logs from firewall, waf,proxy logs, MFA, sandbox, ...network resources however my other search head for apps is getting all data

A distributed architecture with a single instance for 1 indexer, 1 Search Head, 1 Search Head with Enterprise Security, 1 Heavy Forwarder and 1 Deployment server is designed to ensure enhance log search performance. The following are essential components of Distributed Architecture implemented in our setup.

• 1 Search Head with License Master
• 1 Search Head running Enterprise Security App
• 1 Deployment server
• 1 Indexer
• 1 Heavy Forwarder

How can I solve this now, but my ES dashboard like security posture, incident reviews shows data from windows events, logs etc but no network logs

threat intelligence, endpoints, risks, malware, email activity, DNS activity, access, traffic , http, intrusion have not adequate details on firewall,DLP,WAF,MFA,Apex, ....etc

even if i search for user in splunk ES search head normal search no results...

we have all this apps on other search head working fine....we have one indexer peer ....

Need to fix this at priority....please help

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...