Splunk Enterprise

Why is tstats count showing 0 on _internal index?

PickleRick
Ultra Champion

Today I've seen something strange. I was preparing a small workshop for the customer and wanted to show the performance difference between

index=_internal | stats count

and

| tstats count where index=_internal

I was completely baffled when the second search showed me (repeatedly) count of 0.

If I run the search on any other splunk instance I have access to it shows me more or less the same number for both searches (of course they can differ slightly as the _internal is dynamic so a difference of few dozen entries is perfectly understandable).

But this one showed 0 with tstats.

Anyone encountered something like that?

I didn't have time to investigate further, I hope I get some time tomorrow to look into it but I'm puzzled. To make thing more mysterious, for other indexes tstats shows proper counts. It's just the _internal index which lies that it has no events.

It's a 8.2.6 clustered (both indexer cluster and shcluster) installation.

Labels (1)
Tags (2)
0 Karma

BLACKBEARCO
Explorer

Could also be related to https://community.splunk.com/t5/Splunk-Enterprise/what-makes-tstats-on-internal-go-wrong/m-p/572087.

Unfortunately, the resolution in the linked issue did not seem to apply to us. It seemed very specific to the _internal index.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Is _internal tsidx-reduced on that system?

---
If this reply helps you, Karma would be appreciated.
0 Karma

PickleRick
Ultra Champion

I'll have to check that but I don't think so.

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Maybe it’s related to this https://community.splunk.com/t5/Splunk-Search/tstats-is-not-displaying-all-expected-hosts/m-p/602539...

If I recall right I have seen some other too?

https://splunk-usergroups.slack.com/archives/C0YK8DN2H/p1649110401076109 probably another issue related to internal indexes.

r. Ismo

PickleRick
Ultra Champion

Indeed, seems related. Thanks!

0 Karma
Get Updates on the Splunk Community!

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...