Splunk Enterprise Security

tstats errors with Splunk 7.1 + Enterprise Security 5.1?

jhigginsmq
Path Finder

Hi. We've just upgraded to Splunk 7.1 on our ES search head, as well as upgrading ES from 5.0 to 5.1 to meet the compatibility requirements. It's not behaving - all ES dashboard panels powered by data model acceleration, i.e. 99% of them, are displaying 'no results found'. The scheduler has also started skipping the vast majority of searches and I'm sure it must be somehow related to all the scheduled tstats searches which are no longer valid.

After a bit of tail-chasing it looks like a change in the allowed syntax of accelerated data model queries with tstats is to blame: the search below returns results for searching an accelerated datamodel "DM" with dataset "DS"

| tstats summariesonly=t count as status from datamodel=DM where nodename=DS

however all ES searches use this variation of the syntax, which no longer returns any results:

| tstats summariesonly=t count as status from datamodel=DM.DS

I've tested some dummy datamodel searches outside of ES and it looks like this only happens in 7.1; also I can see in the release notes for Splunk 7.1 there is mention of a change in behaviour for datamodel searches ("Data model searches now only use fields that have been defined within the data model").

Has anyone else upgraded to Splunk 7.1/ES 5.1 and had this problem?

0 Karma
1 Solution

jhigginsmq
Path Finder

This has been resolved by upgrading our indexer to 7.1 to match the ES search head.

I was sticking to the rule that the search head version number needs to be greater than or equal to the indexer, but maybe this is a 7.1-specific requirement that they match.

View solution in original post

0 Karma

jhigginsmq
Path Finder

This has been resolved by upgrading our indexer to 7.1 to match the ES search head.

I was sticking to the rule that the search head version number needs to be greater than or equal to the indexer, but maybe this is a 7.1-specific requirement that they match.

0 Karma

jhigginsmq
Path Finder

I've had to roll back to Enterprise Security 5.0 and Splunk 7.0 to restore functionality... Would be good to hear if anyone at Splunk is aware of this problem?

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...