Deployment Architecture

Has anyone seen search returning different numbers of events after upgrading to 6.6.0?

lycollicott
Motivator

I upgraded our DMC (Distributed Management Console) to 6.6.0 last week, but everything else in our environment is still 6.5.3.

This search returns different results on the 6.6 DMC than on the 6.5.3 SHC (Search Head Cluster):

index=_* earliest=-2h@h latest=-1h@h
| stats count by index
| sort index

6.6.0:

index       count   
_audit  49747
_internal   16173711
_introspection  67630 

6.5.3:

index       count   
_audit  33771
_internal   7392283
_introspection  47820 
0 Karma
1 Solution

lycollicott
Motivator

Bah, I'm an idiot.

This all cascaded down from the DMC being on 6.6 and the cluster master being on 6.5. I upgraded the CM and that resolved it.

View solution in original post

lycollicott
Motivator

Bah, I'm an idiot.

This all cascaded down from the DMC being on 6.6 and the cluster master being on 6.5. I upgraded the CM and that resolved it.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...