All Apps and Add-ons

Why are we getting error "The search for datamodel 'TS2' failed to parse, cannot get indexes to search" on a search head with the OPTIC Splunk App?

bigtyma
Communicator

"The search for datamodel 'TS2' failed to parse, cannot get indexes to search"

We are receiving this error on a search head that is hosting the Threatstream/Optic app.

The data model is accelerated and the base search used to generate the constraints is working.

Any ideas or troubleshooting advice is appreciated.

Thank you

0 Karma

jordanperks
Path Finder

I fixed this issue on the Malware Datamodel that ships with CIM app by disabling or editing any eventtype tag search that used a macro and tags malware/attack.

0 Karma

bigtyma
Communicator

Update: I have disabled acceleration for this data model and now the pivot is working correctly. However we would like for acceleration to work. Ideas?

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...