Splunk Search

summariesonly contains no event

dellytaniasetia
Explorer

Hi,

my search command:
tstats summariesonly count as failures from datamodel=Authentication.Authentication where Authentication.action="failure" by Authentication.src

returns 0 event. Is there any setting/config to turn on summariesonly?

It only contains event on specific date which is 20 Dec.

thanks

Tags (2)
0 Karma

cmerriman
Super Champion

you need to have summariesonly=t and the datamodel needs to be accelerated for the time frame you're interested in for results to come back using this argument. Is all of that true? If so, try rebuilding the acceleration and run the search again to see if it picked it up.

Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...