Splunk Enterprise Security

Splunk entreprise security status "Pending..."

splunkcol
Contributor

Has anyone presented this problem?

splunkcol_0-1601267017866.png

 

Labels (1)
0 Karma

inventsekar
Super Champion

Hi....is this a new ES deployment?

is this problem re-occurred multiple times, how often? any browser problems?  

PS ... If any post helped you in any way, pls give a hi-five to the author with an upvote. if your issue got resolved, please accept the reply as solution.. thanks.
0 Karma

splunkcol
Contributor

Yes, it is new, the problem occurs at least once a week.

When the problem is present, no matter how hard I try to solve it, it finally fixes itself.

It seems like a queuing issue, what I have investigated is that the possible cause is that I have activated all the notable event functionalities

This process helped me not to have the problem so frequently, but it still happens https://splunkonbigdata.com/2020/07/21/concurrent-historical-searches-in-splunk/

There are other errors that I have pending to solve and I do not know if they are related

bundle.png

other times when the searches are not completed or the graphics are not loaded, an error appears that refers to loss of connection with the peer, that is, with the 2 indexers, after 2 min it normalizes, but it happens at least 5 times every 10 min

peerforo.png

Tags (3)
0 Karma

jwelch_splunk
Splunk Employee
Splunk Employee

1. This dashboard is fed by a KV Store Collection called "ess_notable_events"

2. The "ess_notable_events collection is fed by a Scheduled Search called " ESS - Notable Events"

3. In order for searches to be run from a SH, the indexing tier must have a "Common Knowledge Bundle" installed on ALL indexers.  If you don't have a common baseline across all indexers the scheduler on the SH will quit running searches.

To me it sounds like you have some issues between your ES SH and your indexing tier, and I would start here for the trouble shooting process.

 a. How big is your bundle on the SH in /opt/splunk/var/run/ *.bundle

b. Is your ES SH on the same network as your Indexers? 

c. Are you system running with plenty of resources and no network connectivity issues between them.

d. you can increase settings like timeouts between the SH and indexers for 8089 communications, but if you are having to do this on a small splunk setup, then something above might be causing your issues.

e. are these physical systems or are you running on an over-subscribed virtualized hardware?

 

Lot of things to look at here, and most all of these are addressable.  If you need further help you might start with a support ticket to help you diagnose the issue .

0 Karma
Get Updates on the Splunk Community!

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...