Splunk Enterprise Security

splunk es content management datamodel is Red

aminab2421
Observer

Hello
i have splunk enterprise 10.0.0 and install splunk enterprise security  8.1.1 
when config cim on splunk es , show datamodel and dataset in search app is ok
like search 
| tstat count from datmodel=Web.Web summariseonly=true
show me event but on content management splunk es show me this error message and datamodel is red
the datamodel s datasets are not ingesting enough data for this content to report accuralely.

how to fix it?

Labels (1)
Tags (2)
0 Karma

aminab2421
Observer

this picture about my problem 

spl1.pngspl2.pngspl3.pngspl4.pngspl5.png

 

 

 

spl4.png

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @aminab2421 

Please can you share the full error message and screenshot of what you're seeing?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...