Splunk Dev

How to leverage the data from tstats query from a datamodel to stats command?

kaur_aman18
New Member

I am using C#SDK to search for | tstats count FROM datamodel=IIS_Data WHERE nodename=IIS_events IIS_events.cs_method='GET'.... but it is failing with "Error in 'tstats' command: This command is not supported in a real-time search".

If we replace tstats with stats and what else we need to make change?

0 Karma

FrankVl
Ultra Champion

Not familiar with the C# SDK and not sure what exactly you want to achieve, but can you not just run it as a normal search instead of a realtime search? Doing realtime searches on an accelerated data model anyway doesn't make much sense.
See https://dev.splunk.com/view/csharp-sdk-pcl/SP-CAAAEYY for the differences and how to run them.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...