I am trying to create a query using tstats from datamodel Malware, one of the sourcetype 'abc' that i want to include is coming up in index search but not in datamodel tstats search, the index is already mapped with Malware datamodel, is this possible?
So, most probably the events that missing has not requires tagging for Malware datamodel. Since datamodels are working based on tags, Malware model searches the events with "malware" and "attack" tags. Please check the missing events tags with below search.
index=missing_index sourcetype=abc | stats count by tag
If you don't see "malware" and "attack" tags you should check eventide and tag settings for missing sourcetypes.