All Apps and Add-ons

User Behavior search error in Tsidxstats 6.0

mwarvi
Explorer

When I attempt to search for a user I get the error "Error in 'TsidxStats': WHERE clause is not an exact query." Our user's come from the pan in the form domain\username. The other search fields appear to work fine. If related, traffic and data events are at 0 as well.

I upgraded to 6.0 from 5.4 by straight upgrading, by "Install from file" and then did a fresh reinstall as well (was fixing other issues).

0 Karma

panguy
Contributor

This has been resolved in 6.0.1

0 Karma

btorresgil
Builder

Thanks for reporting this. I filed a bug here:

https://github.com/PaloAltoNetworks/SplunkforPaloAltoNetworks/issues/65

We'll fix this in App 6.0.1. As a workaround, in the dashboard's source line 4, change $user$ to "$user|s$".

Thanks again!

mwarvi
Explorer

Hi, I looked at the query and it's already set to $user|s$. I changed it to $user$ in case it got flip flopped, and now the search runs without error using *username.

0 Karma

btorresgil
Builder

Thanks for the feedback. If you use $user|s$, don't forget you need the double-quotes around it: "$user|s$". That is most likely the reason for the issue. $user$ also works if you're willing to use a wildcard for the domain like you mentioned.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...