Splunk Enterprise Security

Why is gia_summary index not populating?

Stefanie
Builder

I've been investigating why I started to not receive  ES events for some time now. After upgrading ES, I had to reinstall a lot of the apps that were previously installed & configured. One of the things I have not been able to resolve is how to get ES to detect "Geographically Improbable Access Detected" again. 

My Authentication Datamodel is receiving events again. 

My asset_lookup_by_str has events

However, my asset_lookup_by_cidr does not return results. So I believe this may be causing it.

How can I get the asset_lookup_by_cidr to populate again?

Labels (1)
0 Karma
1 Solution

Stefanie
Builder

Just an update in case anyone in the future has this problem.

I had pull a list of all assets with CIDR information, and then create a lookup for CIDR.

I also populated the data with city, country, lat, long. That seemed to fix it!

View solution in original post

Stefanie
Builder

Just an update in case anyone in the future has this problem.

I had pull a list of all assets with CIDR information, and then create a lookup for CIDR.

I also populated the data with city, country, lat, long. That seemed to fix it!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...