Splunk Cloud Platform

Splunk Cloud Migration Assessment Tool- Preflight check searches not pulling results

prime_x_tech15
Loves-to-Learn

 

I need some assistance with the Splunk Cloud migration assessment tool. We plan to move to Splunk Cloud but there are no results for 2 of the preflight check searches but there is data in the index the search pulls from. The searches are:

| tstats dc(host) AS hosts where `scma_source_internal_index` source=*license_usage.log TERM(Usage) earliest=-24h@h by index

 

And

 

| tstats dc(host) AS hosts where `scma_source_internal_index` sourcetype=splunkd earliest=-4h@h by index

 

I was reading through the troubleshooting guide and it mentioned that there is a bug where tstats doesn’t work well with reading the internal indexes so it states to reach out to Splunk Support(which I have done but no response yet).

The current version of splunk enterprise is 8.2.2.1

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...