I'm totally and utterly new to splunk. Just ran the dockerhub sample, and followed the instructions: https://hub.docker.com/r/splunk/splunk/
I opened the search tab and most search commands seem to work fine. For example, the following command:
| from datamodel:"internal_server.server"
| stats count
Returns a count of 33350.
While this command:
| tstats count from datamodel:"internal_server.server"
as well as this one:
| tstats count
both return zero.
How can I get tstats working in this docker env with the sample datasets?
... View more