Splunk Enterprise Security

tstats errors with Splunk 7.1 + Enterprise Security 5.1?

jhigginsmq
Path Finder

Hi. We've just upgraded to Splunk 7.1 on our ES search head, as well as upgrading ES from 5.0 to 5.1 to meet the compatibility requirements. It's not behaving - all ES dashboard panels powered by data model acceleration, i.e. 99% of them, are displaying 'no results found'. The scheduler has also started skipping the vast majority of searches and I'm sure it must be somehow related to all the scheduled tstats searches which are no longer valid.

After a bit of tail-chasing it looks like a change in the allowed syntax of accelerated data model queries with tstats is to blame: the search below returns results for searching an accelerated datamodel "DM" with dataset "DS"

| tstats summariesonly=t count as status from datamodel=DM where nodename=DS

however all ES searches use this variation of the syntax, which no longer returns any results:

| tstats summariesonly=t count as status from datamodel=DM.DS

I've tested some dummy datamodel searches outside of ES and it looks like this only happens in 7.1; also I can see in the release notes for Splunk 7.1 there is mention of a change in behaviour for datamodel searches ("Data model searches now only use fields that have been defined within the data model").

Has anyone else upgraded to Splunk 7.1/ES 5.1 and had this problem?

0 Karma
1 Solution

jhigginsmq
Path Finder

This has been resolved by upgrading our indexer to 7.1 to match the ES search head.

I was sticking to the rule that the search head version number needs to be greater than or equal to the indexer, but maybe this is a 7.1-specific requirement that they match.

View solution in original post

0 Karma

jhigginsmq
Path Finder

This has been resolved by upgrading our indexer to 7.1 to match the ES search head.

I was sticking to the rule that the search head version number needs to be greater than or equal to the indexer, but maybe this is a 7.1-specific requirement that they match.

0 Karma

jhigginsmq
Path Finder

I've had to roll back to Enterprise Security 5.0 and Splunk 7.0 to restore functionality... Would be good to hear if anyone at Splunk is aware of this problem?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...