Splunk Enterprise Security

Why are the dashboards not displaying any data in the Enterprise Security app?

mcxrisley08
Path Finder

So I recently had to nuke the search head that our Enterprise Security app was running on. I have reinstalled everything and setup search peers but I am having trouble getting any of the dashboards to display any data. Any help with this would be appreciated.

0 Karma

tiagofbmm
Influencer

The data in the ES dashboards is retrieved from the DataModels residing in your indexers.

The first thing to test is if you can search anything from ma data model, like *| from datamodel:. *. Let me know if you have results for any of the datamodels you are using

0 Karma

mcxrisley08
Path Finder

I get nothing when running that string in search.

0 Karma

tiagofbmm
Influencer

Are you specifiying one data model?

Like | from datamodel:"Network_Traffic"."All_Traffic"

0 Karma

alemarzu
Motivator

I believe it is like this

| datamodel Authentication search | table Authentication.*
0 Karma

mcxrisley08
Path Finder

Ok, That search returns a ton of results. I have made some progress and have got my identities and assets lists created in ES. Some of the issues I'm having now are:

1. The two lists do not share a common value, so I'm not sure how to merge or if they can even merged

2. When I run a search Asset/Identity Investigator, It returns a lot of bogus PII events. I do have the demo data disabled, So I'm not sure why these events are being labeled as such.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...