After modifying and renaming the TippingPoint TA, I installed it and I can now see that it is working in Non-ES Search Head and on the ES search head out side of the Enterprise Security application.
Splunk version 5.0.1
Current app: Enterprise Security
version 2.2.0, build 144974
From: https://splunk-ess.domain.com:8000/en-US/app/search/dashboard_live
Search: index="test" sourcetype="tippingpoint"
Result: Works! Tipping point fields are listed for the data.
From: https://splunk-ess.domain.com:8000/en-US/app/SplunkEnterpriseSecuritySuite/flashtimeline
Search: index="test" sourcetype="tippingpoint"
Result: Does NOT Works! Tipping point fields Don't show up.
Question 1: Does changing the name of the TA make a difference to ESS app?
Question 2: Could this be some role, with the user having access to the new TA?
Question 3: Could this be a compatibility issue?
... View more