Reporting

Results page issues after Splunk update

loganac
Engager

We recently updated our Splunk deployment from 6.5 to 7.3.3. We redeployed our server and indexed everything the exact same as before. Same inputs, props, transforms. But we are having a weird issue with some of our reports being identical as the old ones but then anywhere from 15-30% of the results are all jumbled up. I put an example of what we are seeing below

 

source     host    testtype  results  measurement

c://              1           test1          PASS           00.000125

c://              2            c://            UUT SER:    TUE OP:

 

The logs haven't change but it's like is not recognizing the props and transforms.conf for some and pushes the information around for our results. I'm still pretty new to Splunk and have tried to find a question similar to this but haven't found any answer. Thanks for the help

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...