Getting Data In

Compatible commands with Summary Index- Why aren't stats and chart command working?

Poojitha
Communicator

Hi All,

I have created a summary index . I am making use of "sistats count by <fields>" to populate all the fields required. And I see those fields as well. 

The issue is - On this index I am trying to use chart command and also stats count(<field>) as test (chart command in one query and stats count in another query) but its not working. There is no results returned. Instead I use stats command and populate data to summary index , both commands are working.

Please let me know why chart and stats command are not working on the summary index that I have created using sistats command . [sichart as well not working]. I am missing some technical information here.

Regards,
PNV

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

I may be wrong as I haven't used sistats, although I have used summary indexes. My interpretation of the documentation is that to retrieve the stats from the summary index created by the sistats command, you have to use the exact same command apart from substituting the sistats with stats. Similarly, for sichart and chart. You cannot mix them. Therefore, the reason you are not getting results from your summary index with chart is because they were put there by sistats (not sichart).

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...