I just had this issue resolved. Check to see if your indexers are running the same version of splunk as your ES search head. They should be identical. Also make sure to deploy the Splunk_TA_ForIndexers from your ES search head to your indexers.
What is the baseline search for you "Threat_Intelligence" data model? Have you configured it to search specific indexes or changed the root constraints of the DM? Additionally what version of CIM and ES?