Knowledge Management

What's the difference between search&reporting app and quality monitoring app

happybotter
New Member

The search statement like the following:

host = "*****" | rex field=data.textPyaload "time_ms=(?[\s]+)" | timechart span=1m avg(time_ms)

I can get the statistics in search&reporting app, but in quality monitoring app, there are no results. Is there any limit in quality monitoring app that I can't execute rex command?

Tags (1)
0 Karma

adonio
Ultra Champion

what is the "quality monitoring app"?
my thoughts here are that the field extractions for the fields are on app level and therefore you cant see them in your "quality monitoring app"
try and run this from "quality monitring app" ... host=* | fields = data.textPyaload and verify its extracted correctly

0 Karma

happybotter
New Member

Thank you adonio.
There are many different apps in Splunk enterprise, Quality Monitoring is just one of them. I just use Search&Reporting and Quality Monitoring these two apps.
The problem is that I use the same search statement in these two apps, In Search&Reporting, when I run the search, I can get events and statistics, that's what I want. But in Quality Monitoring, I can get events and it's same as Search&Reporting, but can't get statistics.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The problem is not with the rex command, which is available to all apps. You are probably using some knowledge object which is part of the Search & Reporting app and is shared only for app (not global) access. Check the permissions settings on the objects you may have created.

---
If this reply helps you, Karma would be appreciated.
0 Karma

happybotter
New Member

Thank you richgalloway,
I guess there is something wrong with permission, because after run the search statement, the events are same in Search&Reporting and Quality Monitoring app, the difference is we can extract value from log in Search&Reporting app, while can't in Quality Monitoring app.
As you said, Check the permissions settings on the objects you may have created. What's your mean of objects.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Knowledge objects are things like eventtypes, tags, field extractions, etc.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...