Splunk Search

Why can't tstats search sourcetype field specifically?

hketer
Path Finder

Hi All,

I'm running the query 

| tstats count where index=<index name> by sourcetype

No results  
OR 

| tstats values(sourcetype) where index=<index name> by index

and the results for values(sourcetype) is null\empty.

I have up to date data with  no delays in indextime .

I've checked the fields.conf on indexers and I do see the field [sourcetype]

**Also there are sourcetypes that does work and I see the field 

Any ideas how to check this? or what can be the issue?

 

Thanks,
Hen

Labels (1)
0 Karma

gjanders
SplunkTrust
SplunkTrust

I tried:

| tstats values(sourcetype) where index=_internal by index

That works and | tstats count where index=_internal by sourcetype

Also works on 8.2.0

 

Did you have the time range set correctly to find data?

0 Karma
Get Updates on the Splunk Community!

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...