"The search for datamodel 'TS2' failed to parse, cannot get indexes to search"
We are receiving this error on a search head that is hosting the Threatstream/Optic app.
The data model is accelerated and the base search used to generate the constraints is working.
Any ideas or troubleshooting advice is appreciated.
I fixed this issue on the Malware Datamodel that ships with CIM app by disabling or editing any eventtype tag search that used a macro and tags malware/attack.
Update: I have disabled acceleration for this data model and now the pivot is working correctly. However we would like for acceleration to work. Ideas?