Splunk Enterprise Security

Error in TsidxStats append is only valid for pre stats mode

mcronkrite
Splunk Employee
Splunk Employee

In Enterprise Security 3 on Splunk 6, have Websense data that has been tagged "web" and "proxy." Under Security Domains, Network, Web Center, the panels all come up except the bottom two. Top Sources and Top Destinations. The error displayed says "Error in TsidxStats': append is only valid for prestats mode. When I open either search I get the same message. When I pare the search down to not have the tstats append=true it runs fin. So I know the data model is populating. After searching for missing extractions I only have unknowns for status, http_content_type, http_refferer, and user. A fresh install of ES with event gen does not have the error.

1 Solution

mcronkrite
Splunk Employee
Splunk Employee

Turns out the underlying search is wrong, you need to modify the search to add "prestats=true" in front of the "append=true" command. Works now.

View solution in original post

0 Karma

hazekamp
Builder

mcronkrite,

Both the "Top Source" and "Top Destinations" panels on Web Center use the "| tstats" macro. This macro specifies prestats=true.

[tstats]
definition = tstats prestats=true local=`tstats_local` `summariesonly`

Since you mention that a fresh install doesn't have this error, do you by chance have a local override in place or Splunk_TA_opsec installed? If so, would recommend removing these from Splunk_TA_opsec/default/macros.conf because they are overriding the proper ones in SA-Utils:

[tstats]
definition = tstats local=`tstats_local` `summariesonly`

[tstats_local]
definition = false

[summariesonly]
definition = summariesonly=`summariesonly_bool`

[summariesonly_bool]
definition = true

mcronkrite
Splunk Employee
Splunk Employee

Turns out the underlying search is wrong, you need to modify the search to add "prestats=true" in front of the "append=true" command. Works now.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...