Deployment Architecture

Has anyone seen search returning different numbers of events after upgrading to 6.6.0?

lycollicott
Motivator

I upgraded our DMC (Distributed Management Console) to 6.6.0 last week, but everything else in our environment is still 6.5.3.

This search returns different results on the 6.6 DMC than on the 6.5.3 SHC (Search Head Cluster):

index=_* earliest=-2h@h latest=-1h@h
| stats count by index
| sort index

6.6.0:

index       count   
_audit  49747
_internal   16173711
_introspection  67630 

6.5.3:

index       count   
_audit  33771
_internal   7392283
_introspection  47820 
0 Karma
1 Solution

lycollicott
Motivator

Bah, I'm an idiot.

This all cascaded down from the DMC being on 6.6 and the cluster master being on 6.5. I upgraded the CM and that resolved it.

View solution in original post

lycollicott
Motivator

Bah, I'm an idiot.

This all cascaded down from the DMC being on 6.6 and the cluster master being on 6.5. I upgraded the CM and that resolved it.

Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...