-
Notifications
You must be signed in to change notification settings - Fork 180
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
threathunting_file_summary_index is not populated #87
Comments
the same issue, |
The threathunting index is populated via collect commands which are part of scheduled searches defined in savedsearches.conf. As you browse through those searches note the use of macros such as Readme.md encourages you to update field values for index, source, and sourcetype in macro definitions as needed within your environment. You may also need to make sure whitelist csv files are properly imported. If things still aren't working after that please follow up. |
This comment was marked as resolved.
This comment was marked as resolved.
The output of savedsearch titled "[T1036] Masquerading - renamedbin" should be common when no whitelist entries are defined. Copy the search string associated with that and paste it into search input in threathunting namespace (app). Remove last command in search redirecting output to threathunting index via collect command. If you execute what remains over all time do you get results? If not, remove one command at a time and try again. Do you eventually get results? |
yes, it have result. |
i also missing whitelist CVS on board as bellow: |
You can review the source of the about dashboard to examine the underlying search query for the "Whitelist files created/installed.." panel throwing errors for you. To debug the problem, break down the query into its primary elements to see where things go wrong: Run this query: "| rest /servicesNS/-/-/data/lookup-table-files" -- Do you get results? |
Great - if you are getting results now add the "| collect |
i've already fixed it by install ThreatHunting version 1.4. |
See discussion in issue #102. The GitHub version of threathunting app is far ahead of the splunkbase versions and corrects for many issues which I fear you will encounter next. |
I just installed the latest version of the app from GitHub (not Splunkbase) on a new search head. |
I've searched through all of the XML and CONF files in the ThreatHunting application and cannot find how the summary index is being populated. Is there additional configuration to populate this index that is not in the base documentation? Because the index is not being populated, several dashboards are not returning information that I believe were intended to show additional information.
The text was updated successfully, but these errors were encountered: