The ES Network Security Domain dashboard for the fire and EMS network is empty. Which SPL-adjacent resource should the analyst use to learn why the search has nothing to run on?
Select an answer to reveal the explanation.
Short Explanation
An empty Security Domain panel is often a data problem, not a broken dashboard skin. SSE tells you which sourcetypes and CIM maps that search needs. If fire and EMS never sent Network_Traffic-shaped events, the search has nothing to chew.
Full Explanation
When an ES Security Domain dashboard returns no results, the usual cause is missing or unmapped data, not a failed SOAR playbook or a CSS trick. Splunk Security Essentials data-source guidance is the 5.3 resource that shows which sourcetypes and CIM models a use case expects. That explains why the fire/EMS network search has nothing to run on. KV Store repair is ES Admin work and is not the first analyst diagnosis for an empty panel.