Splunk Enterprise Security

Stuck at Analytics Story Onboarding Assistant in Splunk ES Content Update (Splunk Cloud)

azer271
Path Finder

The Analytics Story Onboarding Assistant keeps on displaying "0% uploaded" everytime I press enable the rules (using splunk cloud sc_admin account). Does anyone know why this is happening? Thanks!

Steps to reproduce:

1. In Onboarding (Preview), Select any stories such as active directory

2. Select any detections

azer271_0-1757438561708.png

3. Press Next

4. Press Enable

azer271_1-1757438625857.png

5. 0% uploaded forever

azer271_2-1757438673678.png

6. It said "You can close this window." but no rules are enabled in content management. 

azer271_3-1757438693590.png

azer271_4-1757438937499.png

Its empty. Please help. Thanks.

I will use these rules as an example. these rules are off, but they should be enabled in step 5.

azer271_0-1757439216710.png

 

 

 

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @azer271 

Can you open the network tab of developer tools in your browser and when you click it see what network requests are made and if any of these return any errors? It would be good to know if these requests come back with a positive response or if there is an error with some more information .

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

azer271
Path Finder

It's all 200 status.

However, 99+ error messages appeared in developer tools when I pressed Enable. (mostly mentioning that the error is in es cloud url/static/@xxxx/app/DA-ESS-ContentUpdate/pages/onboarding.js)

azer271_2-1757440454383.pngazer271_3-1757440849963.png

azer271_0-1757441070323.png

 

Errors:

 
Error enabling saved search: TypeError: can't access property "split", document.cookie.split(...).find(...) is undefined
Error enabling saved search: TypeError: can't access property "split" of undefined
Cookie “splunkweb_csrf_token_8443” has been rejected because its expiration date is over the limit.
Thanks. 

 

 

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...