Hello
i have splunk enterprise 10.0.0 and install splunk enterprise security 8.1.1
when config cim on splunk es , show datamodel and dataset in search app is ok
like search
| tstat count from datmodel=Web.Web summariseonly=true
show me event but on content management splunk es show me this error message and datamodel is red
the datamodel s datasets are not ingesting enough data for this content to report accuralely.
how to fix it?
this picture about my problem
Hi @aminab2421
Please can you share the full error message and screenshot of what you're seeing?
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing