Deployment Architecture

Has anyone seen search returning different numbers of events after upgrading to 6.6.0?

lycollicott
Motivator

I upgraded our DMC (Distributed Management Console) to 6.6.0 last week, but everything else in our environment is still 6.5.3.

This search returns different results on the 6.6 DMC than on the 6.5.3 SHC (Search Head Cluster):

index=_* earliest=-2h@h latest=-1h@h
| stats count by index
| sort index

6.6.0:

index       count   
_audit  49747
_internal   16173711
_introspection  67630 

6.5.3:

index       count   
_audit  33771
_internal   7392283
_introspection  47820 
0 Karma
1 Solution

lycollicott
Motivator

Bah, I'm an idiot.

This all cascaded down from the DMC being on 6.6 and the cluster master being on 6.5. I upgraded the CM and that resolved it.

View solution in original post

lycollicott
Motivator

Bah, I'm an idiot.

This all cascaded down from the DMC being on 6.6 and the cluster master being on 6.5. I upgraded the CM and that resolved it.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...