I need some assistance with the Splunk Cloud migration assessment tool. We plan to move to Splunk Cloud but there are no results for 2 of the preflight check searches but there is data in the index the search pulls from. The searches are:
| tstats dc(host) AS hosts where `scma_source_internal_index` source=*license_usage.log TERM(Usage) earliest=-24h@h by index
And
| tstats dc(host) AS hosts where `scma_source_internal_index` sourcetype=splunkd earliest=-4h@h by index
I was reading through the troubleshooting guide and it mentioned that there is a bug where tstats doesn’t work well with reading the internal indexes so it states to reach out to Splunk Support(which I have done but no response yet).
The current version of splunk enterprise is 8.2.2.1