Splunk Search

summariesonly contains no event

dellytaniasetia
Explorer

Hi,

my search command:
tstats summariesonly count as failures from datamodel=Authentication.Authentication where Authentication.action="failure" by Authentication.src

returns 0 event. Is there any setting/config to turn on summariesonly?

It only contains event on specific date which is 20 Dec.

thanks

Tags (2)
0 Karma

cmerriman
Super Champion

you need to have summariesonly=t and the datamodel needs to be accelerated for the time frame you're interested in for results to come back using this argument. Is all of that true? If so, try rebuilding the acceleration and run the search again to see if it picked it up.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...