Hi All,
we had successfully upgraded to Splunk 9.0.4. However, we observed that when using tstats command, we are getting the below message. normal searches are all giving results as expected.
[indexer1,indexer2,indexer3,indexer4.indexer5] When used for 'tstats' searches, the 'WHERE' clause can contain only indexed fields. Ensure all fields in the 'WHERE' clause are indexed. Properly indexed fields should appear in fields.conf.
Any idea why we are getting this and how to resolve it.
... View more