Splunk Search

"Error in 'tstats' command: This command is not supported in a real-time search"

spammenot66
Contributor

I currently have a working tstats search, but when I use real-time, it returns the following error:

Error in 'tstats' command: This command is not supported in a real-time search
0 Karma
1 Solution

woodcock
Esteemed Legend

Not only will it never work but it doesn't even make sense how it could. Use stats instead and have it operate on the events as they come in to your real-time window. Better yet, do not use real-time! It almost certainly will not give you what you desire and it will crater the performance of your splunk cluster.

View solution in original post

woodcock
Esteemed Legend

Not only will it never work but it doesn't even make sense how it could. Use stats instead and have it operate on the events as they come in to your real-time window. Better yet, do not use real-time! It almost certainly will not give you what you desire and it will crater the performance of your splunk cluster.

spammenot66
Contributor

Thanks for the info

0 Karma

somesoni2
Revered Legend

The error message explains it all. Searches with tstats can't be used for real-time searches. What is your requirement here?

Get Updates on the Splunk Community!

Splunk Enterprise Security(ES) 7.3 is approaching the end of support. Get ready for ...

Hi friends!    At Splunk, your product success is our top priority. With Enterprise Security (ES), we're here ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...