I use Splunk v7.2 on a Windows server. I have installed some add-ons and apps. The problem is that any query that uses stat or tstat does not return any result (they just return 0).
For example, this is a query from Modsecurity's app:
| tstats summariesonly=true count from datamodel=modsecurity_alerts
I believe I have installed the app correctly.
In addition to that, some of the queries from Splunk app for Windows infrastructure also don't work, this is one of them:
| inputlookup windows_event_system | dedup Host | stats count
I have been googling for a while, but with no luck. Any help is highly appreciated.
... View more