Hello,
I have an error message in the threat activity dashboard in a Splunk Entreprise Security search head:
[indexer] The search for datamodel 'Threat_Intelligence' failed to parse, cannot get indexes to search !
I disabled acceleration in the threat intelligence data model and I still have the error.
Any help please?
↧