The collections are created "on the fly", that's the whole purpose of nosql, to avoid table schemas. The collections are created when they are "needed", and not at startup as you describe. In short, the atomic_indicators collection is created only when Splice has to store such indicators, meaning it has previously read an IOC file where extractable indicators have been found (like an IPv4 for example). It is possible that the RSS feed include unexpected characters (I don't know, just guessing here). So, what I would recommend is to manually download an IOC file and store it manually in the directory you configured as modular input. Be sure to store a valid OpenIOC file or a STIX file.
For the log part, have a look in the splunkd.log.
Out of curiosity, why do you use Splice and not ES?
... View more