<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tstats where error after upgrading to Splunk 9.0.4 in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-fix-tstats-error-after-upgrading-to-Splunk-9-0-4/m-p/641954#M222379</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/255744"&gt;@keishsplunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't know if something changed in the Splunk last version, but you should try to move the fields in the WHERE condition after the tstats command when they are also the BY fields, something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats count WHERE index=* BY sourcetype host
| search host=your_host&lt;/LI-CODE&gt;&lt;P&gt;or&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats count WHERE index=* host=your_host BY sourcetype&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 02 May 2023 06:35:37 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-05-02T06:35:37Z</dc:date>
    <item>
      <title>How can I fix tstats error after upgrading to Splunk 9.0.4?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-fix-tstats-error-after-upgrading-to-Splunk-9-0-4/m-p/641936#M222374</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;we had successfully upgraded to Splunk 9.0.4.&amp;nbsp; However, we observed that when using tstats command, we are getting the below message. normal searches are all giving results as expected.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;[indexer1,indexer2,indexer3,indexer4.indexer5] When used for 'tstats' searches, the 'WHERE' clause can contain only indexed fields. Ensure all fields in the 'WHERE' clause are indexed. Properly indexed fields should appear in fields.conf.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any idea why we are getting this and how to resolve it.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="keishsplunk_0-1682985422139.png" style="width: 687px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/25167i90D265DCD3355B8D/image-dimensions/687x148?v=v2" width="687" height="148" role="button" title="keishsplunk_0-1682985422139.png" alt="keishsplunk_0-1682985422139.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 13:27:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-fix-tstats-error-after-upgrading-to-Splunk-9-0-4/m-p/641936#M222374</guid>
      <dc:creator>keishsplunk</dc:creator>
      <dc:date>2023-05-02T13:27:04Z</dc:date>
    </item>
    <item>
      <title>Re: tstats where error after upgrading to Splunk 9.0.4</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-fix-tstats-error-after-upgrading-to-Splunk-9-0-4/m-p/641954#M222379</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/255744"&gt;@keishsplunk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't know if something changed in the Splunk last version, but you should try to move the fields in the WHERE condition after the tstats command when they are also the BY fields, something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats count WHERE index=* BY sourcetype host
| search host=your_host&lt;/LI-CODE&gt;&lt;P&gt;or&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;| tstats count WHERE index=* host=your_host BY sourcetype&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2023 06:35:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-fix-tstats-error-after-upgrading-to-Splunk-9-0-4/m-p/641954#M222379</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-05-02T06:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: How can I fix tstats error after upgrading to Splunk 9.0.4?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-fix-tstats-error-after-upgrading-to-Splunk-9-0-4/m-p/650821#M225021</link>
      <description>&lt;P&gt;We are experiencing the same issue after Upgrading from 8.2.9 to 9.0.5. Any Updates / Infos available?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 12:53:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-fix-tstats-error-after-upgrading-to-Splunk-9-0-4/m-p/650821#M225021</guid>
      <dc:creator>mika703</dc:creator>
      <dc:date>2023-07-17T12:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: How can I fix tstats error after upgrading to Splunk 9.0.4?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-fix-tstats-error-after-upgrading-to-Splunk-9-0-4/m-p/650832#M225026</link>
      <description>&lt;P&gt;Change the SPL syntax as such -&amp;nbsp;&lt;/P&gt;&lt;P&gt;| tstats count where index=* by sourcetype,host | search sourcetype=* host=heavy-forwarder-1&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2023 13:30:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-fix-tstats-error-after-upgrading-to-Splunk-9-0-4/m-p/650832#M225026</guid>
      <dc:creator>keishsplunk</dc:creator>
      <dc:date>2023-07-17T13:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: How can I fix tstats error after upgrading to Splunk 9.0.4?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-can-I-fix-tstats-error-after-upgrading-to-Splunk-9-0-4/m-p/650938#M225058</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/255744"&gt;@keishsplunk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 07:03:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-can-I-fix-tstats-error-after-upgrading-to-Splunk-9-0-4/m-p/650938#M225058</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-07-18T07:03:29Z</dc:date>
    </item>
  </channel>
</rss>

