Splunk Search

Stats Results After Upgrade

dpwtheitguy
Loves-to-Learn Lots

All,

Just upgraded to 8.2.1 last night and noticed something today with stats.

# This search returns 160k+ events
index=netfw
162276

# This returns a 0 in Smart mode, this search returned data in 8.1.x how ever no data in 8.2.1
index=netfw | stats count
0

# Same search in Verbose mode however returns the count
index=netfw | stats count
162276

Shouldn't Smart mode have returned the count correctly also? It did work that way in 8.1

Labels (1)
0 Karma

vivekarora
Engager

Yes, It should return the same result in both smart and verbose mode.

I am also using Splunk 8.2.1

Attaching the screenshot for your reference.

I am using index=snow, its returing 99 events.

vivekarora_0-1627708660914.png

 

When I am using stats command, index=snow|stats count in verbose mode, its showing same 99 events

vivekarora_1-1627708751298.png

If I am using same stats command in smart mode, its showing same result

index=snow | stats count

 

vivekarora_2-1627708840996.png

 

Hence, the output of stats command in smart and verbose mode in splunk 8.2.1 is same.

 

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...