Hello,
Where do I find information on how to troubleshoot the below error:
2022-12-05 15:21:53,383+0000 INFO pid=299674 tid=MainThread file=threatmatch.py:run:404 | status="This modular input does not execute on a search head cluster member" msg="will_execute="False" config="SHC" msg="Deselected based on SHC master selection algorithm." master_host="None" use_alpha="None" exclude_master="None""
The sourcetype is in the _internal index and the sourcetype=threatintel:threatmatch
I have a hard time finding documentation that points me to a solution.
Hi @Azeemering,
I suppose that you have a Search Head Cluster with installed ES and there's a misconfiguration in your cluster.
I hint to open a case to Splunk Support because it seems to be a relevant issue and I never encountered it.
Ciao.
Giuseppe