All Apps and Add-ons

Anomali ThreatStream Community App: What does "Error in TsidxStats": Could not find datamodel: TS_optic" mean and how do I fix it?

pmchao
New Member

I am new to the Splunk world, but I was trying to use Anomali ThreatStream Community App and a search but get the following errors:
(1) Error in "TsidxStats": Could not find datamodel: TS_Optic
(2) The search job has failed due to an error. You may be able view job in the "Job Inspector"

My question is: what is "datamodel : TS_Optic"? How do I create one?

0 Karma

himynamesdave
Contributor

Hey @pmchao -

I work @ Anomali and can help you fix this ASAP.

We've just released a new version of the app with some fixes. Although this was not a known issue can you configure the new app on your Splunk instance and report if this issue persists?

Hopefully it will be resolved, if not, please can you reply the steps you went through to configure the app (including any data you're using -- sources, sourcetypes, etc) so we can begin to troubleshoot?

-dave

0 Karma

martin_mueller
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...