Splunk Enterprise Security

Splunk Enterprise Security: Why am I getting "[indexer] The search for datamodel 'Threat_Intelligence' failed to parse, cannot get indexes to search"?

Afef
Communicator

Hello,

I have an error message in the threat activity dashboard in a Splunk Entreprise Security search head:

[indexer] The search for datamodel 'Threat_Intelligence' failed to parse, cannot get indexes to search !

I disabled acceleration in the threat intelligence data model and I still have the error.

Any help please?

0 Karma

rickylee
New Member

I just had this issue resolved. Check to see if your indexers are running the same version of splunk as your ES search head. They should be identical. Also make sure to deploy the Splunk_TA_ForIndexers from your ES search head to your indexers.

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

What is the baseline search for you "Threat_Intelligence" data model? Have you configured it to search specific indexes or changed the root constraints of the DM? Additionally what version of CIM and ES?

0 Karma

Afef
Communicator

hi, i didn't change any thing.. CIM and ES latest versions.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...