Under Threshold templates I only have "Custom" and nothing else. This was an upgrade from 1.2.0 but the ITOA kvstore was clear prior due to upgrade issues.
Restarted Splunk and it appears to be working now.
View solution in original post