Splunk Enterprise Security

tstats errors with Splunk 7.1 + Enterprise Security 5.1?

jhigginsmq
Path Finder

Hi. We've just upgraded to Splunk 7.1 on our ES search head, as well as upgrading ES from 5.0 to 5.1 to meet the compatibility requirements. It's not behaving - all ES dashboard panels powered by data model acceleration, i.e. 99% of them, are displaying 'no results found'. The scheduler has also started skipping the vast majority of searches and I'm sure it must be somehow related to all the scheduled tstats searches which are no longer valid.

After a bit of tail-chasing it looks like a change in the allowed syntax of accelerated data model queries with tstats is to blame: the search below returns results for searching an accelerated datamodel "DM" with dataset "DS"

| tstats summariesonly=t count as status from datamodel=DM where nodename=DS

however all ES searches use this variation of the syntax, which no longer returns any results:

| tstats summariesonly=t count as status from datamodel=DM.DS

I've tested some dummy datamodel searches outside of ES and it looks like this only happens in 7.1; also I can see in the release notes for Splunk 7.1 there is mention of a change in behaviour for datamodel searches ("Data model searches now only use fields that have been defined within the data model").

Has anyone else upgraded to Splunk 7.1/ES 5.1 and had this problem?

0 Karma
1 Solution

jhigginsmq
Path Finder

This has been resolved by upgrading our indexer to 7.1 to match the ES search head.

I was sticking to the rule that the search head version number needs to be greater than or equal to the indexer, but maybe this is a 7.1-specific requirement that they match.

View solution in original post

0 Karma

jhigginsmq
Path Finder

This has been resolved by upgrading our indexer to 7.1 to match the ES search head.

I was sticking to the rule that the search head version number needs to be greater than or equal to the indexer, but maybe this is a 7.1-specific requirement that they match.

0 Karma

jhigginsmq
Path Finder

I've had to roll back to Enterprise Security 5.0 and Splunk 7.0 to restore functionality... Would be good to hear if anyone at Splunk is aware of this problem?

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...