All Apps and Add-ons

User Behavior search error in Tsidxstats 6.0

mwarvi
Explorer

When I attempt to search for a user I get the error "Error in 'TsidxStats': WHERE clause is not an exact query." Our user's come from the pan in the form domain\username. The other search fields appear to work fine. If related, traffic and data events are at 0 as well.

I upgraded to 6.0 from 5.4 by straight upgrading, by "Install from file" and then did a fresh reinstall as well (was fixing other issues).

0 Karma

panguy
Contributor

This has been resolved in 6.0.1

0 Karma

btorresgil
Builder

Thanks for reporting this. I filed a bug here:

https://github.com/PaloAltoNetworks/SplunkforPaloAltoNetworks/issues/65

We'll fix this in App 6.0.1. As a workaround, in the dashboard's source line 4, change $user$ to "$user|s$".

Thanks again!

mwarvi
Explorer

Hi, I looked at the query and it's already set to $user|s$. I changed it to $user$ in case it got flip flopped, and now the search runs without error using *username.

0 Karma

btorresgil
Builder

Thanks for the feedback. If you use $user|s$, don't forget you need the double-quotes around it: "$user|s$". That is most likely the reason for the issue. $user$ also works if you're willing to use a wildcard for the domain like you mentioned.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...