Splunk Search

tstats unable to get any results when specifying dataset in FROM clause

att35
Builder

Hi,

We are in the process of migrating all Apps/Config's from an older standalone instance(7.2.4.2) to a newer SHC(8.1.1). A datamodel was also migrated along with the App and appears to be working fine in terms of acceleration statistics. But when I try to access using tstats, format that worked previously returns nothing.

| tstats summariesonly=t count FROM datamodel="modelname.dataset" by dataset.field

DM_inspect.png

But if I do not mention dataset in the FROM cause, it works just fine.

| tstats summariesonly=t count FROM datamodel="modelname" by dataset.field

 

Could I have missed something during the migration? What could be causing the previous command to not work.

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...