Splunk Search

tstats summariesonly=t

coreyf311
Path Finder

as admin i can see results running a tstats summariesonly=t search. Same search run as a user returns no results. As that same user, if I remove the summariesonly=t option, and just run a tstats...... search that user can return results. The Datamodel has everyone read and admin write permissions.

Tags (1)
0 Karma

p_gurav
Champion

Data model is accelerated? Also can you try using allow_old_summaries=t instead of summariesonly=t.

0 Karma

coreyf311
Path Finder

I did use allow_old_summaries and it works for the user. Not sure what that does exactly thats different and why summariesonly doesnt work for that user.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...