All Apps and Add-ons

S.o.S. Errors view no longer showing event counts for clustered events

paulstark
Path Finder

Ive seen this behavior in many deployments. In the Splunk on Splunk errors page, I select 'Group Similar Events' and the cluster_count does not show up. why?

Ellen
Splunk Employee
Splunk Employee

Since 6.0.3, the cluster search command no longer returns the cluster_count by default.

eg. showcount = false

Prior to 6.0.3, the default of showcount = true

Since displaying the count could have a performance impact, from 6.0.3+ a user can pass showcount = true to the cluster command to return the cluster_count.

eg. index=_internal | cluster showcount=true | table cluster_count, _raw

SPL-83560 updates the documentation for the cluster command default showcount option

0 Karma

hexx
Splunk Employee
Splunk Employee

This is caused by a bug with Splunk Enterprise (reference: SPL-83560) which will be fixed in a future maintenance release.

hexx
Splunk Employee
Splunk Employee

Yes, the issue is indeed with the "cluster" command.

thisissplunk
Builder

Does this also explain why the cluster_count field added to events by the cluster commmand aren't showing up anymore as well? Only cluster_label is showing up now for me.

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...