Hello. I'm super new to Splunk(love to tool for assessing JuniperFW logs) but I'm being tasked at a new job with something out of my zone. I'm a Palo Alto guy but my boss would like our Forcepoint logs to run through this app. I have it installed but this string tstats average =false count FROM datamodel=mail_log gives me an error saying it can't find that datamodel. Now this model is fully operational under PP for Proofpoint with all permissions available to all. I did check that. Can anyone help me with this? I'm using Splunk Enterprise 8.2.4 and DomainTools 4.3.0. Thank you in advance!
... View more