Splunk Search

summariesonly contains no event

dellytaniasetia
Explorer

Hi,

my search command:
tstats summariesonly count as failures from datamodel=Authentication.Authentication where Authentication.action="failure" by Authentication.src

returns 0 event. Is there any setting/config to turn on summariesonly?

It only contains event on specific date which is 20 Dec.

thanks

Tags (2)
0 Karma

cmerriman
Super Champion

you need to have summariesonly=t and the datamodel needs to be accelerated for the time frame you're interested in for results to come back using this argument. Is all of that true? If so, try rebuilding the acceleration and run the search again to see if it picked it up.

*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>