It really depends on your deployment topology, but you can try installing the app on all core instances of splunk and enabling the visualizations on the Search Head. Also, make sure you have props. / transforms. configured to set the correct sourcetype=Cisco:ISE:Syslog
... View more