Anytime I run a search with a transforming command, the count field is populating in the left column. For some reason, Splunk has been doing this for all users and its messing with all of our dashboards. Anyone have a similar issue and a fix?
The fix for this was to comment out the line:
phased_execution_mode = singlethreaded
in limits.conf of Enterprise Security.
The fix for this was to comment out the line:
phased_execution_mode = singlethreaded
in limits.conf of Enterprise Security.
Good Evening @dzayas ,
I am not able to reproduce that error as well. Something you can do to fix that is:
index=fw
| stats count by description
| table description, count
Please let me know if that helps
I have done that but its a simple spot fix. This isn't normal operation for Splunk. Plus, it's messing up all the prebuilt dashboards in Enterprise Security.
I can't reproduce the issue in Splunk 7.1.1. Which version of Splunk Enterprise you are using?
Splunk Core - 7.2.1
Splunk ES - 5.2.2
I can't reproduce this issue also on Splunk version 7.2.4.
Splunk Core - 7.2.1
Splunk ES - 5.2.2
@Dshys,
Can you try Splunk file integrity check and update here if you find any errors?
./splunk validate files