Splunk Enterprise Security

splunk cloud es notable index empty

Splunk_rocks
Path Finder

Hello Splunkers
we have splunk managed cloud ES and i have enabled all correlation searches as per doc the way we do on Prem ES.
Nothing showing ES posture dashboards and notable events are empty no data under notable index
we mapped data models and we validated data with data model fields every thing is there
but ES and notable index is empty BW this is splunk managed cloud product

0 Karma

woodcock
Esteemed Legend

There are many steps for setting up ES that you should do before enabling correlation searches. On top of that, enabling ALL of them is an absolutely horrible idea and nobody should ever do that. Generally ES is sold with PS and your PS team should know better than that and should have done all the setup. What setup did you do and what documentation did you/they follow for setup?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...