So I recently had to nuke the search head that our Enterprise Security app was running on. I have reinstalled everything and setup search peers but I am having trouble getting any of the dashboards to display any data. Any help with this would be appreciated.
The data in the ES dashboards is retrieved from the DataModels residing in your indexers.
The first thing to test is if you can search anything from ma data model, like *| from datamodel:. *. Let me know if you have results for any of the datamodels you are using
I get nothing when running that string in search.
Are you specifiying one data model?
Like | from datamodel:"Network_Traffic"."All_Traffic"
I believe it is like this
| datamodel Authentication search | table Authentication.*
Ok, That search returns a ton of results. I have made some progress and have got my identities and assets lists created in ES. Some of the issues I'm having now are: