Splunk Search

summariesonly contains no event



my search command:
tstats summariesonly count as failures from datamodel=Authentication.Authentication where Authentication.action="failure" by Authentication.src

returns 0 event. Is there any setting/config to turn on summariesonly?

It only contains event on specific date which is 20 Dec.


Tags (2)
0 Karma

Super Champion

you need to have summariesonly=t and the datamodel needs to be accelerated for the time frame you're interested in for results to come back using this argument. Is all of that true? If so, try rebuilding the acceleration and run the search again to see if it picked it up.

Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!