-
Notifications
You must be signed in to change notification settings - Fork 179
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Hello, my threat hunting dashboard keeps showing 0 data, but the Activity by time per day dashboard underneath is circulating. #106
Comments
The version of the threathunting app on splunkbase is far behind the version available on GitHub. Can you replace your install and then share whether problem still exists? Otherwise the screenshot of your configuration panel crops out values of macro definitions. Macro definitions or missing indexes are the most likely problem sources. |
Hello Still having the same problem |
Please post an updated screenshot of the app dashboard panel. Make sure to include all of the macro panel values. Also please include a screenshot of any event in the index having your sysmon data. I did not realize that the ThreatHunting app is now up to date on Splunkbase until about an hour ago. After that I removed the ThreatHunting app from my server and then installed it again (from Splunkbase) and things are working fine for me. |
Do you have the splunk add on for Microsoft windows installed? If not , try that and let me know. |
|
Please run the following search and send screenshot of results: earliest=-24h index=windows | stats count, dc(EventCode), latest(_raw) by index, sourcetype, source |
|
Glad to hear the dashboard is working now! As for the other statements, you included them in an inputs.conf deployed to a windows endpoint right? |
Thank you. It has been solved. |
splunk.version: 9.0.2
threathunting is downloaded from the splunk app
I really do not know how to solve
The text was updated successfully, but these errors were encountered: