Splunk Search

Why are Splunk queries not returning anything in table?

venugoski
Explorer

Splunk queries not returning anything in table. I see events matching for these queries but nothing under 'Statistics' section.

1.

index=address-validation RESP_MARKER | rex field=log "\"operationPath\"\:\"(?<path>\w+).*\"operationType\"\:\"(?<type>\w+).*\"region\"\:\"(?<reg>\w+).*" | table path, type, reg

2. 

index=club-finder RESP_MARKER | rex field=log "\"operationPath\"\:\"\/(?<path>\w+).*\"operationType\"\:\"(?<type>\w+).*\"region\"\:\"(?<reg>\w+).*\"totalTime\"\:(?<timeTaken>\w+)" | table type, path, timeTaken, reg

Labels (2)
Tags (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The queries do not contain statistics-generating commands (stats, timechart, etc.) so there is nothing for the Statistics tab to show.

---
If this reply helps you, Karma would be appreciated.

venugoski
Explorer

i dont see the stats coming here with stats command as well 

index=address-validation RESP_MARKER | rex field=log "\"operationPath\"\:\"(?<path>\w+).*\"operationType\"\:\"(?<type>\w+).*\"region\"\:\"(?<reg>\w+).*" | stats count by path, type, reg

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Make sure the path, type, and reg fields are not null.  The stats command will not return results for null groupBy fields.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Monitoring Postgres with OpenTelemetry

Behind every business-critical application, you’ll find databases. These behind-the-scenes stores power ...

Mastering Synthetic Browser Testing: Pro Tips to Keep Your Web App Running Smoothly

To start, if you're new to synthetic monitoring, I recommend exploring this synthetic monitoring overview. In ...

Splunk Edge Processor | Popular Use Cases to Get Started with Edge Processor

Splunk Edge Processor offers more efficient, flexible data transformation – helping you reduce noise, control ...