I just discovered that indexed fields with periods in them are not tstats
able in my 7.2.1 environment. Is this a known thing? Is it a bug?
For those who would like to play along, if you have INDEXED_EXTRACTIONS = json
events, then you surely have some index-time fields with periods in them. First find them:
index=foo AND sourcetype=json AND index.field.with.periods=*
Then verify that it is index-time like this (it should also return events; if not, then index.field.with.periods
is not index-time).
index=foo AND sourcetype=json AND index.field.with.periods::*
Then test for fail like this:
|tstats first("index.field.with.periods") AS this_should_work_but_will_not WHERE index=foo AND sourcetype=json
I edited and added the pipe. What version of Splunk (Search Head and Indexers)?
Yes it does. ver 7.2.0