Splunk Search

Why do transforming commands not work after upgrade to Splunk 8?

sistemistiposta
Path Finder

Hello,

   I have recently upgraded from Splunk 7 to Splunk 8.2.4.

After the upgrade, I noticed that some transform commands such as chart or stats do not work in smart and fast mode.

 

For instance:

index=main | chart count by host

returns the expected results in detailed mode. It returns 0 results in smart and fast mode.

 

Ps:

The transaction command still works, but I have to select the fields I want with fields in place of table. In Splunk 7 table works too.

 

I would like that stats and chart commands still work in fast search mode, as it happened in Splunk 7. Could you help me to revert the Splunk 7 working mode?

Thank you very much

Kind Regards

Marco

Labels (1)
0 Karma

landster
Explorer

Hello @sistemistiposta,

Yes, we completed that update immediately following the update to 8.2.5.  That is interesting...   It also seems the issue may exist beyond transforming commands as I have seen it on a simple table command.  I am also waiting eagerly on a response.

0 Karma

sistemistiposta
Path Finder

Aaaah yes, it seems the same issue.

Many days ago I opened a support ticket, as @isoutamo suggested.

We will see...

 

Kind Regards

Ciao

Marco

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @landster,

this is adifferent situation because , with your solution, you don't consider in your results the duplicated events you have, my hont is to try to understand why you have duplicated events!

Anyway, it's better to put this question in a separated post so more people can help you to solve your problem.

Ciao.

Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...