Splunk Search

tstats by index by month Error in 'TsidxStats': WHERE clause is not an exact query

daymar23
Observer

Hello Community! 

I am trying to get the record count by index that I am getting per month in Splunk. I am using this search with tstats, because there are millions of records per month and from I read this is more efficient than the stats command.  

 

| tstats count WHERE (index=*) BY index _time span=1mon
| timechart span=1mon count

 

But I don't know why I am receiving this error: 

 

Error in 'TsidxStats': WHERE clause is not an exact query

 

Can anyone help me to know what I am doing wrong? 

Thanks 

 

 

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That query works fine on 8.1.  What version are you using?  Have you tried without the parentheses?

---
If this reply helps you, Karma would be appreciated.
0 Karma

daymar23
Observer

I have Version:7.2.1 😞 

Yes I have already tried without parentheses.

Do you know how I can do it in this version? 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Sorry, I don't know.  Perhaps upgrading to 7.3.x will help (7.2 is not supported now).

---
If this reply helps you, Karma would be appreciated.
0 Karma

allenclarke
New Member

I get the same issue.  Can't get any searches with tstats to run, they all error in the same way. 

 

Running Splunk 8.2

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...