Splunk Enterprise Security

Splunk Enterprise Security: Dashboards not loading data

RK_sp1unk
New Member

We have a indexer , heavy forwarder, 2 search head , 1 deployment server .
The splunk enterprise Search head dashboards are pulling data and is looking good.
The other search head for enterprise security , dashboards are not pulling data.
I checked the data models are there , apps are updated.
Saw an distributed search alert stating "the rest uri https://10.102.102.212:8089 is not connecting as peer status is 2", not sure is it because of that.
However need urgent help how to get at least default Splunk ES dashboards like security posture,incident review etc to show data.
Please share your thoughts

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...