Splunk Search

summariesonly contains no event

dellytaniasetia
Explorer

Hi,

my search command:
tstats summariesonly count as failures from datamodel=Authentication.Authentication where Authentication.action="failure" by Authentication.src

returns 0 event. Is there any setting/config to turn on summariesonly?

It only contains event on specific date which is 20 Dec.

thanks

Tags (2)
0 Karma

cmerriman
Super Champion

you need to have summariesonly=t and the datamodel needs to be accelerated for the time frame you're interested in for results to come back using this argument. Is all of that true? If so, try rebuilding the acceleration and run the search again to see if it picked it up.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...