<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why do some searches only display statistics and not Events? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371972#M44950</link>
    <description>&lt;P&gt;"So basically, Splunk isn't analyzing regular events to generate the data shown on this screenshot, so it hasn't gathered those events for you to view. "&lt;/P&gt;

&lt;P&gt;Thanks for the explanation of tstats. So the more complicated question would be:&lt;/P&gt;

&lt;P&gt;How do I get Splunk to analyze the regular events to generate the data shown?&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jan 2018 22:24:22 GMT</pubDate>
    <dc:creator>summitsplunk</dc:creator>
    <dc:date>2018-01-03T22:24:22Z</dc:date>
    <item>
      <title>Why do some searches only display statistics and not Events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371970#M44948</link>
      <description>&lt;P&gt;Below is a screen shot from my Fortinet FortiGate App for Splunk. In this case I'm clicking the search "Threat By Severity" on the Threat Dashboard. I noticed that I cannot drill down to events and it's only showing "statistics". &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4093iB78C7178D1BF7BFD/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 21:20:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371970#M44948</guid>
      <dc:creator>summitsplunk</dc:creator>
      <dc:date>2018-01-03T21:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: Why do some searches only display statistics and not Events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371971#M44949</link>
      <description>&lt;P&gt;The query in your screenshot starts with &lt;CODE&gt;tstats&lt;/CODE&gt;, a generating command which returns statistical data based on analysis of the tsidx files, not the events themselves. More information about &lt;CODE&gt;tstats&lt;/CODE&gt; can be found here:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Tstats"&gt;https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Tstats&lt;/A&gt;&lt;BR /&gt;
This answer also provides some good plain-English explanations of what &lt;CODE&gt;tstats&lt;/CODE&gt; is:&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/186938/what-is-tstats-and-why-is-so-much-faster-than-stat.html"&gt;https://answers.splunk.com/answers/186938/what-is-tstats-and-why-is-so-much-faster-than-stat.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;So basically, Splunk isn't analyzing regular events to generate the data shown on this screenshot, so it hasn't gathered those events for you to view. &lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 21:30:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371971#M44949</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2018-01-03T21:30:56Z</dc:date>
    </item>
    <item>
      <title>Re: Why do some searches only display statistics and not Events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371972#M44950</link>
      <description>&lt;P&gt;"So basically, Splunk isn't analyzing regular events to generate the data shown on this screenshot, so it hasn't gathered those events for you to view. "&lt;/P&gt;

&lt;P&gt;Thanks for the explanation of tstats. So the more complicated question would be:&lt;/P&gt;

&lt;P&gt;How do I get Splunk to analyze the regular events to generate the data shown?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 22:24:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371972#M44950</guid>
      <dc:creator>summitsplunk</dc:creator>
      <dc:date>2018-01-03T22:24:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why do some searches only display statistics and not Events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371973#M44951</link>
      <description>&lt;P&gt;I haven't used the Fortinet app on Splunk, so I'm just making some educated guesses based on the documentation I see on Splunkbase at &lt;A href="https://splunkbase.splunk.com/app/2800/#/details"&gt;https://splunkbase.splunk.com/app/2800/#/details&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you followed the default install, it looks like you should be able to find the events that are being used to populate the &lt;CODE&gt;ftnt_fos&lt;/CODE&gt; data model by searching for &lt;CODE&gt;sourcetype=fgt_traffic&lt;/CODE&gt;. (I'm basing this guess on step 5 in the documentation, where a screenshot shows a search for this sourcetype.) &lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 14:26:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371973#M44951</guid>
      <dc:creator>elliotproebstel</dc:creator>
      <dc:date>2018-01-04T14:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: Why do some searches only display statistics and not Events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371974#M44952</link>
      <description>&lt;P&gt;can you change the drilldown query string from:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    &amp;lt;drilldown&amp;gt;
      &amp;lt;link&amp;gt;
        &amp;lt;![CDATA[
            /app/SplunkAppForFortinet/search?q=`fgt_utm` severity="$click.name2$" earliest=$click.value$ [| stats count | eval latest = $click.value$ %2b 300 | fields latest]
          ]]&amp;gt;
      &amp;lt;/link&amp;gt;
    &amp;lt;/drilldown&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;to following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;    &amp;lt;drilldown&amp;gt;
      &amp;lt;link&amp;gt;
        &amp;lt;![CDATA[
            /app/SplunkAppForFortinet/search?q=| datamodel "ftnt_fos" "utm" search | search log.utm.gseverity="$click.value$"&amp;amp;earliest=$time_token.earliest$&amp;amp;latest=$time_token.latest$
          ]]&amp;gt;
      &amp;lt;/link&amp;gt;
    &amp;lt;/drilldown&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;in this file on your splunk search head:&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/apps/SplunkAppForFortinet/default/data/ui/views/threat_dashboard.xml&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 18:59:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371974#M44952</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2018-01-04T18:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Why do some searches only display statistics and not Events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371975#M44953</link>
      <description>&lt;P&gt;Thanks for your input I've modified the drilldown as you suggested however I still cannot view the related events from this query.   &lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 22:01:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371975#M44953</guid>
      <dc:creator>summitsplunk</dc:creator>
      <dc:date>2018-01-04T22:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why do some searches only display statistics and not Events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371976#M44954</link>
      <description>&lt;P&gt;but what did it print out?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 23:04:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371976#M44954</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2018-01-04T23:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Why do some searches only display statistics and not Events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371977#M44955</link>
      <description>&lt;P&gt;It appears that it added a "critical column which is nice. I'm hoping you can see the attacked picture below. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://drive.google.com/file/d/19VPCVdztOH_XNiHV2kXNf8cduj0D5xFA/view?usp=sharing"&gt;https://drive.google.com/file/d/19VPCVdztOH_XNiHV2kXNf8cduj0D5xFA/view?usp=sharing&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jan 2018 23:42:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371977#M44955</guid>
      <dc:creator>summitsplunk</dc:creator>
      <dc:date>2018-01-04T23:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why do some searches only display statistics and not Events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371978#M44956</link>
      <description>&lt;P&gt;this is not what the query i gave you should show.&lt;BR /&gt;
maybe you are editing the wrong line.&lt;BR /&gt;
Line 24 should be the line to be replaced with:&lt;BR /&gt;
/app/SplunkAppForFortinet/search?q=| datamodel "ftnt_fos" "utm" search | search log.utm.gseverity="$click.value$"&amp;amp;earliest=$time_token.earliest$&amp;amp;latest=$time_token.latest$&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:29:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371978#M44956</guid>
      <dc:creator>jerryzhao</dc:creator>
      <dc:date>2020-09-29T17:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: Why do some searches only display statistics and not Events?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371979#M44957</link>
      <description>&lt;P&gt;What I see on line 24 &lt;A href="https://drive.google.com/file/d/1lX41MEvqqYkvhn2DTAu6ISGluv8ozPfa/view?usp=sharing"&gt;https://drive.google.com/file/d/1lX41MEvqqYkvhn2DTAu6ISGluv8ozPfa/view?usp=sharing&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;The Code I edited&lt;BR /&gt;
&lt;A href="https://drive.google.com/file/d/1hF2-tk7cNq1dYqwvoSe57rJtB93MSTmc/view?usp=sharing"&gt;https://drive.google.com/file/d/1hF2-tk7cNq1dYqwvoSe57rJtB93MSTmc/view?usp=sharing&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jan 2018 00:15:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Why-do-some-searches-only-display-statistics-and-not-Events/m-p/371979#M44957</guid>
      <dc:creator>summitsplunk</dc:creator>
      <dc:date>2018-01-05T00:15:17Z</dc:date>
    </item>
  </channel>
</rss>

