Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AppLocker Dashboard Issue - No Policy Review Data #3021

Open
matchstickboy opened this issue Jun 22, 2024 · 1 comment
Open

AppLocker Dashboard Issue - No Policy Review Data #3021

matchstickboy opened this issue Jun 22, 2024 · 1 comment
Labels
bug Something isn't working

Comments

@matchstickboy
Copy link

Describe the bug

Dashboard is mostly working as expected, seeing Audit Events and Event Code Analysis data. but no data displayed in Policy Review

###**Screen Shot
Capture

Expected behavior

Expect to see logged events in the Policy Review section, but only seeing "no search results returned"

App Version:

  • DA-ESS-ContentUpdate: 4.33.0

Additional context

Have a single windows server collecting forwarded Applocker events from multiple endpoints and writing them to the "Forwarded Events" log on the server acting as the Windows Event Collector.

Splunk UF on the server has the following inputs.conf:

[WinEventLog://ForwardedEvents]
disabled =0
start_from = oldest
current_only = 0
evt_resolve_ad_obj = 1
checkpointInterval = 5
index = applocker
renderXml = 1

The applocker SearchMacro has definition has been set to:
index=applocker

@matchstickboy matchstickboy added the bug Something isn't working label Jun 22, 2024
@patel-bhavin
Copy link
Contributor

patel-bhavin commented Oct 17, 2024

@matchstickboy - Are you able to run the searches from the dashboard manually ? I wonder if you dont have any events specific to show in your environment. Is this a live splunk environment or a splunk lab with applocker data? The dashboard works fine in our test environment!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants