<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Transforming commands no more work after upgrade to Splunk 8 in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/620289#M215625</link>
    <description>&lt;P&gt;Ryan,&amp;nbsp; Thank you for bringing this forward and I will work to get your input to the Dev team.&amp;nbsp; Vanessa&lt;/P&gt;</description>
    <pubDate>Wed, 09 Nov 2022 14:29:52 GMT</pubDate>
    <dc:creator>vblue</dc:creator>
    <dc:date>2022-11-09T14:29:52Z</dc:date>
    <item>
      <title>Why do transforming commands not work after upgrade to Splunk 8?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585536#M204004</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;I have recently upgraded from Splunk 7 to Splunk 8.2.4.&lt;/P&gt;
&lt;P&gt;After the upgrade, I noticed that some transform commands such as &lt;STRONG&gt;chart&lt;/STRONG&gt; or &lt;STRONG&gt;stats&lt;/STRONG&gt;&amp;nbsp;do not work in smart and fast mode.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For instance:&lt;/P&gt;
&lt;PRE&gt;index=main | chart count by host&lt;/PRE&gt;
&lt;P&gt;returns the expected results in detailed mode. It returns 0 results in smart and fast mode.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ps:&lt;/P&gt;
&lt;P&gt;The &lt;STRONG&gt;transaction&lt;/STRONG&gt; command still works, but I have to select the fields I want with &lt;STRONG&gt;fields&lt;/STRONG&gt; in place of &lt;STRONG&gt;table&lt;/STRONG&gt;. In Splunk 7 &lt;STRONG&gt;table&lt;/STRONG&gt; works too.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would like that &lt;STRONG&gt;stats&lt;/STRONG&gt;&amp;nbsp;and &lt;STRONG&gt;chart&lt;/STRONG&gt; commands still work in fast search mode, as it happened in Splunk 7. Could you help me to revert the Splunk 7 working mode?&lt;/P&gt;
&lt;P&gt;Thank you very much&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 16:14:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585536#M204004</guid>
      <dc:creator>sistemistiposta</dc:creator>
      <dc:date>2022-02-17T16:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585539#M204007</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/50591"&gt;@sistemistiposta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I have Splunk 8.2.4 and commands as chart or stats run with the host field.&lt;/P&gt;&lt;P&gt;Are you meaning that you haven't results in the Events tab or that you haven't resuls in Events and in Statistics tab?&lt;/P&gt;&lt;P&gt;Obviously being chart a streaming command I have results in the Statistics Tab in all the modes (Fast. Smart and Verbose) but I have events only in Verbose in Events Tab.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 11:54:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585539#M204007</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-02-17T11:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585543#M204010</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;probably something related your other configurations / your environment as this works ok in my environment.&lt;/P&gt;&lt;P&gt;When you you have run this what you found from Job inspector's search.log or Job Details Dashboard (easier to read)?&lt;/P&gt;&lt;P&gt;I got e.g.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="isoutamo_0-1645098964641.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18018i8F71ED8BFEF99035/image-size/medium?v=v2&amp;amp;px=400" role="button" title="isoutamo_0-1645098964641.png" alt="isoutamo_0-1645098964641.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 11:56:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585543#M204010</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-02-17T11:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585592#M204031</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp; thank you for the interesting. It's not easy to debug, because I found it happens only sometime. I can see this with &lt;STRONG&gt;timechart&lt;/STRONG&gt; in place of &lt;STRONG&gt;chart&lt;/STRONG&gt;. See here:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="detailed search: it works always" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18022iAFABFF7981FE4061/image-size/large?v=v2&amp;amp;px=999" role="button" title="detailed.png" alt="detailed search: it works always" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;detailed search: it works always&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="fast search: it works sometime during time" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18023iB31828E9C8F7A894/image-size/large?v=v2&amp;amp;px=999" role="button" title="fast.png" alt="fast search: it works sometime during time" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;fast search: it works sometime during time&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't understand why.&lt;/P&gt;&lt;P&gt;The search log doesn't show errors:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;normalizedSearch&lt;/TD&gt;&lt;TD&gt;litsearch index=main | addinfo type=count label=prereport_events | fields keepcolorder=t "_time" "prestats_reserved_*" "psrsvd_*" | prebin _time span=rtspan | prestats count by _time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;numPreviews&lt;/TD&gt;&lt;TD&gt;8&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;optimizedSearch&lt;/TD&gt;&lt;TD&gt;| search index=main | timechart count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;phase0&lt;/TD&gt;&lt;TD&gt;litsearch index=main | addinfo type=count label=prereport_events track_fieldmeta_events=true | fields keepcolorder=t "_time" "prestats_reserved_*" "psrsvd_*" | prebin _time span=rtspan | prestats count by _time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;phase1&lt;/TD&gt;&lt;TD&gt;timechart count&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;pid&lt;/TD&gt;&lt;TD&gt;674509&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;priority&lt;/TD&gt;&lt;TD&gt;5&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;provenance&lt;/TD&gt;&lt;TD&gt;UI:Search&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;reduceSearch&lt;/TD&gt;&lt;TD&gt;bin _time span=rtspan | sistats count AS "count" by _time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;remoteSearch&lt;/TD&gt;&lt;TD&gt;litsearch index=main | addinfo type=count label=prereport_events track_fieldmeta_events=true | fields keepcolorder=t "_time" "prestats_reserved_*" "psrsvd_*" | prebin _time span=rtspan | prestats count by _time&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;reportSearch&lt;/TD&gt;&lt;TD&gt;timechart count&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 15:41:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585592#M204031</guid>
      <dc:creator>sistemistiposta</dc:creator>
      <dc:date>2022-02-17T15:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585596#M204032</link>
      <description>&lt;P&gt;Ciao Giuseppe,&lt;/P&gt;&lt;P&gt;&amp;nbsp; thank you for the reply. Yes I know that chart or stats commands hide events in fast or smart mode. It's not here the problem.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 15:45:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585596#M204032</guid>
      <dc:creator>sistemistiposta</dc:creator>
      <dc:date>2022-02-17T15:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585598#M204033</link>
      <description>&lt;P&gt;This is quite interesting &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;How about if you are adding&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main host=* 
| chart count by host
```or timechart ...```&lt;/LI-CODE&gt;&lt;P&gt;This should found all events where host is defined (which should be true for all events).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this issue only in main and some special sourcetype or for all indexes and source types?&lt;/P&gt;&lt;P&gt;Maybe it's time for splunk support to find if this is bug or some configuration issue?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 15:49:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585598#M204033</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-02-17T15:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585602#M204035</link>
      <description>&lt;P&gt;Oh yes, I tried the by-clause. It's the same: your search&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=main host=* 
| timechart count by host&lt;/LI-CODE&gt;&lt;P&gt;reports results by hosts until 13:20 only in "fast" mode.&lt;/P&gt;&lt;P&gt;Yes, I tried other analogue searches changing index and sourcetype: it's the same for all them.&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 16:00:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585602#M204035</guid>
      <dc:creator>sistemistiposta</dc:creator>
      <dc:date>2022-02-17T16:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585604#M204036</link>
      <description>&lt;P&gt;How about changing host to e.g. source? Did it work then or not?&lt;/P&gt;&lt;P&gt;Just try to wondering if issue is your host definition (if you have any props/transforms which override default host definition).&lt;/P&gt;&lt;P&gt;Are you sure that there is ingested events &amp;nbsp;or could there be some delays?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Feb 2022 17:17:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585604#M204036</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-02-17T17:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585671#M204056</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;yes, if I count by source the statistics stop at 13:20 too.&lt;/P&gt;&lt;P&gt;There are events, of course, because if I search in &lt;STRONG&gt;detailed mode&lt;/STRONG&gt; I see the full statistics.&lt;/P&gt;&lt;P&gt;I can try to ask for the official support... I can't understand how to debug... The search log doesn't show me errors or timeouts...&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 07:55:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/585671#M204056</guid>
      <dc:creator>sistemistiposta</dc:creator>
      <dc:date>2022-02-18T07:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586502#M204295</link>
      <description>&lt;P&gt;I'm curious if you have a resolution yet?&lt;/P&gt;&lt;P&gt;I recently came across a different, but similar issue and it was resolved when I added&amp;nbsp; "| dedup _raw" to my code.&amp;nbsp; I am still uncertain why it made a difference though.&lt;BR /&gt;&lt;BR /&gt;Failed:&lt;BR /&gt;index=myindex eventName=myevent hostName=myhostname&lt;BR /&gt;| timechart limit=0 span=1h avg(value) as value by eventType&lt;BR /&gt;| table...&lt;BR /&gt;&lt;BR /&gt;Success:&lt;BR /&gt;index=myindex eventName=myevent hostName=myhostname&lt;BR /&gt;| dedup _raw&lt;BR /&gt;| timechart limit=0 span=1h avg(value) as value by eventType&lt;BR /&gt;| table...&lt;/P&gt;</description>
      <pubDate>Thu, 24 Feb 2022 22:02:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586502#M204295</guid>
      <dc:creator>landster</dc:creator>
      <dc:date>2022-02-24T22:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586535#M204302</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/50591"&gt;@sistemistiposta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;tel me if I can help you more, or, please accept an answer for the other people of Community.&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 06:25:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586535#M204302</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-02-25T06:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586537#M204303</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/160861"&gt;@landster&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;this is adifferent situation because , with your solution, you don't consider in your results the duplicated events you have, my hont is to try to understand why you have duplicated events!&lt;/P&gt;&lt;P&gt;Anyway, it's better to put this question in a separated post so more people can help you to solve your problem.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 06:28:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586537#M204303</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-02-25T06:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586551#M204313</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/160861"&gt;@landster&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;yes, If I add "| dedup _raw" it works!&amp;nbsp;&lt;/P&gt;&lt;P&gt;but I suspect this could be a kind of trick in order to make the search as &lt;EM&gt;verbose&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;It's like you add "| fields *" in &lt;EM&gt;fast&lt;/EM&gt; mode. You really perform a &lt;EM&gt;smart&lt;/EM&gt; search.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adding&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| dedup _raw&lt;/LI-CODE&gt;&lt;P&gt;to all my search unfortunately is not a solution for me... and sometimes I could have expected duplicated events (such as when I use&amp;nbsp;&lt;EM&gt;&lt;SPAN&gt;mvcombine&lt;/SPAN&gt;&lt;/EM&gt;). I haven't found a solution yet.&lt;/P&gt;&lt;P&gt;This doesn't happen (or I haven't never noticed) in Splunk 7.x.&lt;/P&gt;&lt;P&gt;Thank you for all the hints.&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 08:00:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586551#M204313</guid>
      <dc:creator>sistemistiposta</dc:creator>
      <dc:date>2022-02-25T08:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586569#M204322</link>
      <description>Definitely you should create a support case for this even you can avoid it with that dedup as it's only a workaround.</description>
      <pubDate>Fri, 25 Feb 2022 09:34:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586569#M204322</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-02-25T09:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586599#M204329</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/50591"&gt;@sistemistiposta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It is not a permanent solution for me either, and I have a support ticket opened with Splunk.&amp;nbsp; I will let you know what i find out.&amp;nbsp; I was mainly curious if we were experiencing the same problem.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 13:21:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586599#M204329</guid>
      <dc:creator>landster</dc:creator>
      <dc:date>2022-02-25T13:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586601#M204331</link>
      <description>&lt;P&gt;Aaaah yes, it &lt;EM&gt;seems&lt;/EM&gt; the same issue.&lt;/P&gt;&lt;P&gt;Many days ago I opened a support ticket, as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;suggested.&lt;/P&gt;&lt;P&gt;We will see...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Ciao&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Fri, 25 Feb 2022 13:28:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/586601#M204331</guid>
      <dc:creator>sistemistiposta</dc:creator>
      <dc:date>2022-02-25T13:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/587006#M204440</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/160861"&gt;@landster&lt;/a&gt;&amp;nbsp;and all community,&lt;/P&gt;&lt;P&gt;&amp;nbsp; I noticed that also &lt;EM&gt;verbose searches&lt;/EM&gt; can't work, if they contain a subsearch with transforming commands.&lt;/P&gt;&lt;P&gt;Ie:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[ search host=alice* | stats count by host  | fields host ] ...&lt;/LI-CODE&gt;&lt;P&gt;could not work. Instead&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[ search host=alice* | dedup host | fields host ] ...&lt;/LI-CODE&gt;&lt;P&gt;always works.&lt;/P&gt;&lt;P&gt;Just a question. Maybe it is not relevant.&amp;nbsp; Do you have already upgraded the &lt;STRONG&gt;kvstore&lt;/STRONG&gt; to &lt;STRONG&gt;wiredTiger&lt;/STRONG&gt;?&lt;/P&gt;&lt;P&gt;This change and the upgrade to Splunk 8.2.5 are my only upgrade which I have done recently.&lt;/P&gt;&lt;P&gt;I'm still waiting news from Splunk support.&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; Marco&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 13:49:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/587006#M204440</guid>
      <dc:creator>sistemistiposta</dc:creator>
      <dc:date>2022-03-01T13:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/587016#M204445</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/50591"&gt;@sistemistiposta&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Yes, we completed that update immediately following the update to 8.2.5.&amp;nbsp; That is interesting...&amp;nbsp;&amp;nbsp; It also seems the issue may exist beyond transforming commands as I have seen it on a simple table command.&amp;nbsp; I am also waiting eagerly on a response.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 14:15:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/587016#M204445</guid>
      <dc:creator>landster</dc:creator>
      <dc:date>2022-03-01T14:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/587048#M204460</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/50591"&gt;@sistemistiposta&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We upgraded the storage engine on both our test instance and our production instance, along with the update to 8.2.5.&amp;nbsp;&amp;nbsp; Only the production environment is exhibiting the symptom, however.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 15:50:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/587048#M204460</guid>
      <dc:creator>landster</dc:creator>
      <dc:date>2022-03-01T15:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: Transforming commands no more work after upgrade to Splunk 8</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/587053#M204461</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/160861"&gt;@landster&lt;/a&gt;&amp;nbsp;, the same for me.&lt;/P&gt;&lt;P&gt;In our test environment I didn't notice the problem.&lt;/P&gt;&lt;P&gt;In production we have a large amount of data, so I could suspect that also the data volume can affect this issue.&lt;/P&gt;&lt;P&gt;At this point I hope for news from support...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 16:16:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Why-do-transforming-commands-not-work-after-upgrade-to-Splunk-8/m-p/587053#M204461</guid>
      <dc:creator>sistemistiposta</dc:creator>
      <dc:date>2022-03-01T16:16:37Z</dc:date>
    </item>
  </channel>
</rss>

