Hi,
my search command:
tstats summariesonly
count as failures from datamodel=Authentication.Authentication where Authentication.action="failure" by Authentication.src
returns 0 event. Is there any setting/config to turn on summariesonly
?
It only contains event on specific date which is 20 Dec.
thanks
you need to have summariesonly=t
and the datamodel needs to be accelerated for the time frame you're interested in for results to come back using this argument. Is all of that true? If so, try rebuilding the acceleration and run the search again to see if it picked it up.