Splunk Enterprise

Proofpoint TAP Modulat Input: Showing Wrong Dashboards

jaridaycock
Explorer

I am trying to ingest Proofpoint TAP logs to our Splunk enviornment and noticed that our Proofpoint TAP app is showing the Dashboards for the Cisco FMC app for some reason. I thought maybe I could resolve it by deleting the app and reinstalling it but even after doing that it is still showing the FMC app. Has anyone seen this before? I tried looking for other posts with this issue but my search is coming up short.

TAP_Dashboard.PNG

Labels (3)
0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

Hello, looks like an issue with app/TA UI visibility. I have seen issues like this whenever there is TA with the missing config. Are you trying to use: https://splunkbase.splunk.com/app/3681 ?

is this Splunk Enterprise or Cloud? What Version? Can you please go to Manage Apps > Your app > Edit Properties > Visible  > Just to make sure.

 

 

Thanks

 

0 Karma

jaridaycock
Explorer

Hello,

We are using Splunk Enterprise version 9.1.2. Yes that is the correct app we are trying to use and I verified that the visibility is enabled.

TAP_App.PNG

0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

Do you have a heavy forwarder in your environment to install this add-on,  this is  a modular input on a heavy forwarder, please disable this on the search head and install this on one of your heavy forwarder.

 

 

0 Karma
Get Updates on the Splunk Community!

Digital Resilience Assessment Launch | How prepared are you for disruption?

Disruption is inevitable. The question is – how prepared are you to handle it? In today’s fast-moving digital ...

Buttercup Games: Further Dashboarding Techniques (Part 2)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Index This | What is the next number in the series? 7,645 5,764 4,576…

February 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...