I am trying to ingest Proofpoint TAP logs to our Splunk enviornment and noticed that our Proofpoint TAP app is showing the Dashboards for the Cisco FMC app for some reason. I thought maybe I could resolve it by deleting the app and reinstalling it but even after doing that it is still showing the FMC app. Has anyone seen this before? I tried looking for other posts with this issue but my search is coming up short.
Hello, looks like an issue with app/TA UI visibility. I have seen issues like this whenever there is TA with the missing config. Are you trying to use: https://splunkbase.splunk.com/app/3681 ?
is this Splunk Enterprise or Cloud? What Version? Can you please go to Manage Apps > Your app > Edit Properties > Visible > Just to make sure.
Thanks
Hello,
We are using Splunk Enterprise version 9.1.2. Yes that is the correct app we are trying to use and I verified that the visibility is enabled.
Do you have a heavy forwarder in your environment to install this add-on, this is a modular input on a heavy forwarder, please disable this on the search head and install this on one of your heavy forwarder.