All Apps and Add-ons

User Behavior search error in Tsidxstats 6.0

mwarvi
Explorer

When I attempt to search for a user I get the error "Error in 'TsidxStats': WHERE clause is not an exact query." Our user's come from the pan in the form domain\username. The other search fields appear to work fine. If related, traffic and data events are at 0 as well.

I upgraded to 6.0 from 5.4 by straight upgrading, by "Install from file" and then did a fresh reinstall as well (was fixing other issues).

0 Karma

panguy
Contributor

This has been resolved in 6.0.1

0 Karma

btorresgil
Builder

Thanks for reporting this. I filed a bug here:

https://github.com/PaloAltoNetworks/SplunkforPaloAltoNetworks/issues/65

We'll fix this in App 6.0.1. As a workaround, in the dashboard's source line 4, change $user$ to "$user|s$".

Thanks again!

mwarvi
Explorer

Hi, I looked at the query and it's already set to $user|s$. I changed it to $user$ in case it got flip flopped, and now the search runs without error using *username.

0 Karma

btorresgil
Builder

Thanks for the feedback. If you use $user|s$, don't forget you need the double-quotes around it: "$user|s$". That is most likely the reason for the issue. $user$ also works if you're willing to use a wildcard for the domain like you mentioned.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...