Hi Spunkers,
My organization runs splunk enterprise. I see that there is a TA installed for Anomali Threatstream. I am trying to find out which index and sourcetype that it's logs are categorized in so I can run searches against it. It's my understanding that when the app was setup it would have had to been given an index and sourcetype.
What is the best way I can accomplish this?