Deployment Architecture

Has anyone seen search returning different numbers of events after upgrading to 6.6.0?

lycollicott
Motivator

I upgraded our DMC (Distributed Management Console) to 6.6.0 last week, but everything else in our environment is still 6.5.3.

This search returns different results on the 6.6 DMC than on the 6.5.3 SHC (Search Head Cluster):

index=_* earliest=-2h@h latest=-1h@h
| stats count by index
| sort index

6.6.0:

index       count   
_audit  49747
_internal   16173711
_introspection  67630 

6.5.3:

index       count   
_audit  33771
_internal   7392283
_introspection  47820 
0 Karma
1 Solution

lycollicott
Motivator

Bah, I'm an idiot.

This all cascaded down from the DMC being on 6.6 and the cluster master being on 6.5. I upgraded the CM and that resolved it.

View solution in original post

lycollicott
Motivator

Bah, I'm an idiot.

This all cascaded down from the DMC being on 6.6 and the cluster master being on 6.5. I upgraded the CM and that resolved it.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...