Before Splunk 5.0.0 , when I had results summarized with stats or timechart, the name of the function was converted using underscores. To call the result back I had to use the "_". This changed with 5.*, to call back you need to use the exact function call.
Example :
* | timechart span=1h sum(GB) by source
index=summary search_name=mysummarysearch earliest=24h | stats sum(sum_GB_) by source
index=summary search_name=mysummarysearch earliest=24h | stats sum(sum(GB)) by source
I had to go over my searches and fix them, they were able to retrieve all my data
I had to go over my searches and fix them, they were able to retrieve all my data