All Apps and Add-ons

Anomali ThreatStream Community App: What does "Error in TsidxStats": Could not find datamodel: TS_optic" mean and how do I fix it?

pmchao
New Member

I am new to the Splunk world, but I was trying to use Anomali ThreatStream Community App and a search but get the following errors:
(1) Error in "TsidxStats": Could not find datamodel: TS_Optic
(2) The search job has failed due to an error. You may be able view job in the "Job Inspector"

My question is: what is "datamodel : TS_Optic"? How do I create one?

0 Karma

himynamesdave
Contributor

Hey @pmchao -

I work @ Anomali and can help you fix this ASAP.

We've just released a new version of the app with some fixes. Although this was not a known issue can you configure the new app on your Splunk instance and report if this issue persists?

Hopefully it will be resolved, if not, please can you reply the steps you went through to configure the app (including any data you're using -- sources, sourcetypes, etc) so we can begin to troubleshoot?

-dave

0 Karma

martin_mueller
SplunkTrust
SplunkTrust
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...