Deployment Architecture

Has anyone seen search returning different numbers of events after upgrading to 6.6.0?

lycollicott
Motivator

I upgraded our DMC (Distributed Management Console) to 6.6.0 last week, but everything else in our environment is still 6.5.3.

This search returns different results on the 6.6 DMC than on the 6.5.3 SHC (Search Head Cluster):

index=_* earliest=-2h@h latest=-1h@h
| stats count by index
| sort index

6.6.0:

index       count   
_audit  49747
_internal   16173711
_introspection  67630 

6.5.3:

index       count   
_audit  33771
_internal   7392283
_introspection  47820 
0 Karma
1 Solution

lycollicott
Motivator

Bah, I'm an idiot.

This all cascaded down from the DMC being on 6.6 and the cluster master being on 6.5. I upgraded the CM and that resolved it.

View solution in original post

lycollicott
Motivator

Bah, I'm an idiot.

This all cascaded down from the DMC being on 6.6 and the cluster master being on 6.5. I upgraded the CM and that resolved it.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...