I used query index=testindex _raw=* and successfully returned 200+ result. However, when I added stats index=testindex _raw=* | stats count by host, no result returned. Is there anything missing when I use stats command? Below is the splunk search result of the 1st query (without stats): 21/02/11 21:23:45.000 2021_2_10-15_0_0_,1274423072.0 Major = 1274423072.0 Time = 2021_2_10-15_0_0_ host = splunktest index = testindex source = C:\git\splunktest\first.txt sourcetype = csv 21/02/11 21:23:45.000 2021_2_10-14_59_0_,1274423072.0 Major = 1274423072.0 Time = 2021_2_10-14_59_0_ host = splunktest index = testindex source = C:\git\splunktest\first.txt sourcetype = csv 21/02/11 21:23:45.000 2021_2_10-14_58_0_,1274423072.0 Major = 1274423072.0 Time = 2021_2_10-14_58_0_ host = splunktest index = testindex source = C:\git\splunktest\first.txt sourcetype = csv
... View more