Splunk Enterprise Security

Enerprise Security posture is empty

m1ster1985
Explorer

I have installed Enterprise Security App. 

I review Security Domain, in particular, Access and Network sections and I see many events coming from my AD, Office 365, and Firewalls.

However, Security Posture dashboards are all empty. 

I have checked permissions and given full access. 

Could you advise what I should check to fix it?

m1ster1985_0-1632126882373.png

 

Labels (2)
0 Karma
1 Solution

ro_mc
Path Finder

You can also check index=notable.

Notable events are typically generated as an Adaptive Response Action for a correlation search.

You can see this from the Enterprise Security menu bar under Configure -> Content -> Content Management. Correlation searches must be enabled and search conditions met before notable events are generated and become visible from the Security Posture and Incident Review dashboards.

You can use existing correlation searches, use the Splunk ES Content Update (ESCU) app from Splunkbase at https://splunkbase.splunk.com/app/3449/, or generate your own searches using the guidance at https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Correlationsearchoverview.

You can also edit the Security Posture dashboard to display other key indicators, but the default ones cover the main security domains and frameworks used by Enterprise Security.

 

View solution in original post

0 Karma

ro_mc
Path Finder

You can also check index=notable.

Notable events are typically generated as an Adaptive Response Action for a correlation search.

You can see this from the Enterprise Security menu bar under Configure -> Content -> Content Management. Correlation searches must be enabled and search conditions met before notable events are generated and become visible from the Security Posture and Incident Review dashboards.

You can use existing correlation searches, use the Splunk ES Content Update (ESCU) app from Splunkbase at https://splunkbase.splunk.com/app/3449/, or generate your own searches using the guidance at https://docs.splunk.com/Documentation/ES/6.6.0/Admin/Correlationsearchoverview.

You can also edit the Security Posture dashboard to display other key indicators, but the default ones cover the main security domains and frameworks used by Enterprise Security.

 

0 Karma

m1ster1985
Explorer

Thank you very much.

I enabled objects in the Content Management and Security Posture instantly filled with different events. 

 

Azeemering
Builder

Did you really check though? The Security Posture dashboard is 100% driven by notables.

Did you check if there are any notables generated?

If you go the the Incident Review dashboard. Do you have any notables there?

Do you get any results when you run the underlying spl queries? ;

| `es_notable_events`

or without macro and even more simple:

| inputlookup es_notable_events

m1ster1985
Explorer

Thank you for the reply. 

The Incident Review dashboard is also empty.

m1ster1985_1-1632134372637.png

I have executed a request and nothing empty result. 

m1ster1985_0-1632134290030.png

But when I review events using Security Domains, I see a lot of events.

For instance, Access Centre.

m1ster1985_2-1632134437542.png

Very strange, I have no idea why this is happening in this way. 

 

 

0 Karma

Azeemering
Builder

Why would it be strange? No notables means no data in the Security Posture dashboard....

Next step for you would be to figure out why you do not have any notables.
Create some test notables.

You can create them this way:

makeresults | eval dest="splunkftw" | sendalert notable

I'm  more worried about the lack of ES knowledge and the task that you got to install and configure ES...

Check this:

https://dev.splunk.com/enterprise/docs/devtools/enterprisesecurity/notableeventsplunkes/

m1ster1985
Explorer

Thank you very much.

You are right, I do not have appropriate knowledge in ES.  😞

Hope, I will fix it in the near future. 

After enabling objects in Content Management, I started receiving notable events. 

 

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...