Splunk Search

Why can't tstats search sourcetype field specifically?

hketer
Path Finder

Hi All,

I'm running the query 

| tstats count where index=<index name> by sourcetype

No results  
OR 

| tstats values(sourcetype) where index=<index name> by index

and the results for values(sourcetype) is null\empty.

I have up to date data with  no delays in indextime .

I've checked the fields.conf on indexers and I do see the field [sourcetype]

**Also there are sourcetypes that does work and I see the field 

Any ideas how to check this? or what can be the issue?

 

Thanks,
Hen

Labels (1)
0 Karma

gjanders
SplunkTrust
SplunkTrust

I tried:

| tstats values(sourcetype) where index=_internal by index

That works and | tstats count where index=_internal by sourcetype

Also works on 8.2.0

 

Did you have the time range set correctly to find data?

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...