Splunk Search

mstats and mcatalog simply does not work

deodion
Path Finder

I try to use mstats and mcatalog command
it just simply does not work, I think its Splunk settings side Im missing,

such as this:

| mstats sum(bytes) latest(_time) where index=metrics_app_dest_survey by app_name

Im using admin account, is there anything wrong with user role capability?
I only see one thing relevant list_metrics_catalog is added capability, but still not working,

What am I missing? thanks!

0 Karma
1 Solution

deodion
Path Finder

Hello thaggie,
thanks for replying, the problem with this is simply that I didnt setup the index type correctly, the index type should be metric.

View solution in original post

0 Karma

deodion
Path Finder

Hello thaggie,
thanks for replying, the problem with this is simply that I didnt setup the index type correctly, the index type should be metric.

0 Karma

thaggie_splunk
Splunk Employee
Splunk Employee

When you execute:

| mcatalog values(metric_name) where index=metrics_app_dest_survey

Do you get any values back?

You can't aggregate time so you need to remove latest(_time), this should work:

| mstats sum(bytes) where index=metrics_app_dest_survey by app_name
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...