I've lately installed MISP add-on app from Splunk to integrate our MISP environment feed to Splunk app using the URL and the Auth API. That being said, I was able to configure it with details required in MISP add-on app. However, after the configuration, I'm getting the following error:
(Restricting results of the "rest" operator to the local instance because you do not have the "dispatch_rest_to_indexers" capability).
Furthermore, by looking into the role capabilities under Splunk UI setting, I dont see "dispatch_rest_to_indexers" role either.
Could someone please assist?