Splunk Search
Highlighted

"Error in 'tstats' command: This command is not supported in a real-time search"

Communicator

I currently have a working tstats search, but when I use real-time, it returns the following error:

Error in 'tstats' command: This command is not supported in a real-time search
0 Karma
Highlighted

Re: "Error in 'tstats' command: This command is not supported in a real-time search"

SplunkTrust
SplunkTrust

The error message explains it all. Searches with tstats can't be used for real-time searches. What is your requirement here?

Highlighted

Re: "Error in 'tstats' command: This command is not supported in a real-time search"

Esteemed Legend

Not only will it never work but it doesn't even make sense how it could. Use stats instead and have it operate on the events as they come in to your real-time window. Better yet, do not use real-time! It almost certainly will not give you what you desire and it will crater the performance of your splunk cluster.

View solution in original post

Highlighted

Re: "Error in 'tstats' command: This command is not supported in a real-time search"

Communicator

Thanks for the info

0 Karma