Enterprise Security is installed, but the Access and Network domain dashboards stay empty even though firewall and Windows logs are indexed. What is missing?
Select an answer to reveal the explanation.
Short Explanation
ES dashboards drink from CIM cups. A TA that tags and maps fields is what fills those cups; installing ES on raw unmapped logs leaves the cups dry. More licenses and SOAR playbooks do not map src and dest.
Full Explanation
Technical add-ons tag events and map vendor fields into CIM so data models and ES domain dashboards populate. Installing Enterprise Security without CIM-compliant sourcetypes yields empty Access, Network, and similar views even when raw logs exist. License size, indexer topology, and SOAR playbooks are not the mapping layer. Connect TA field mapping to populated CIM and ES dashboards.