<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple stats file from summary index in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682586#M19031</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Is that possible to check who run the adhoc search of backfill of summary index from the _audit index ?&lt;/P&gt;</description>
    <pubDate>Mon, 01 Apr 2024 08:11:31 GMT</pubDate>
    <dc:creator>uagraw01</dc:creator>
    <dc:date>2024-04-01T08:11:31Z</dc:date>
    <item>
      <title>Multiple stats file from summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682552#M19026</link>
      <description>&lt;P&gt;Hello Splunkers!!&lt;/P&gt;&lt;P&gt;Every week, my report runs and gathers the results under the summary index=analyst. You can see that several stash files are being created for the specific report in the screenshot below. Conversely, multiple stash files won't be created for other reports.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Report with multiple stash files.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_2-1711950956151.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29981i865912B0244356EF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_2-1711950956151.png" alt="uagraw01_2-1711950956151.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Report with no duplicate no stash files.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_3-1711951009773.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29982iE5AD52D0CFD678D4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_3-1711951009773.png" alt="uagraw01_3-1711951009773.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Please provide me an assistance on this.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 06:25:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682552#M19026</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-04-01T06:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple stats file from summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682559#M19027</link>
      <description>&lt;P&gt;I have further investigated and seen that the Info_search_time for all the stash file is same. Please suggest any significance behind it ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_1-1711954696809.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29986i415BD8FF3414B2DA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_1-1711954696809.png" alt="uagraw01_1-1711954696809.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 06:58:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682559#M19027</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-04-01T06:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple stats file from summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682560#M19028</link>
      <description>&lt;P&gt;What is the issue?&lt;/P&gt;&lt;P&gt;Stash files are used by Splunk to serialise the events so that they can be indexed.&lt;/P&gt;&lt;P&gt;The source can be overridden in the collect command.&lt;/P&gt;&lt;P&gt;These are from two different reports - if you are interested, you should look at the settings for those reports to see the differences in how they are sent to the summary index.&lt;/P&gt;&lt;P&gt;As for the times, where the times are almost identical, this is likely to be due to a cron job, which potentially is from a unix-based system, whereas the sources with more different times look like they are from a Windows-based system, which doesn't usually have cron.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 07:09:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682560#M19028</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-04-01T07:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple stats file from summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682579#M19029</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both the Saved searches are running at the same time. In your view, Is this causing the issue ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1711957923786.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29987i461863202C6A1D33/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1711957923786.png" alt="uagraw01_0-1711957923786.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_1-1711957962806.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29988i4D513B293E594757/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_1-1711957962806.png" alt="uagraw01_1-1711957962806.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 07:54:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682579#M19029</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-04-01T07:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple stats file from summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682580#M19030</link>
      <description>&lt;P&gt;It is not clear whether there is an issue - to me it looks like the reports that were run on Feb 29th were done manually / ad hoc to back-fill the summary index for the earlier weeks before the schedule was set up and running correctly.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 08:00:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682580#M19030</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-04-01T08:00:16Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple stats file from summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682586#M19031</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Is that possible to check who run the adhoc search of backfill of summary index from the _audit index ?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 08:11:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682586#M19031</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-04-01T08:11:31Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple stats file from summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682587#M19032</link>
      <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;What caused the creation of these "D:\Splunk\var\spool\splunk\99ec742c0c976c35_events.stash_new" files? Instead of spool files, that should be the name of the report.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Do stash-spool files get created when a saved search is used ad hoc or backfill? When there are no spool files being created by scheduled?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 08:24:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682587#M19032</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-04-01T08:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple stats file from summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682589#M19033</link>
      <description>&lt;P&gt;The stash files are usually created by the collect command.&lt;/P&gt;&lt;P&gt;Depending on your retention settings, you may be able to find out who ran the report from your _audit index.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 08:32:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682589#M19033</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-04-01T08:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple stats file from summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682590#M19034</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Manual runs of the search and to collect into summary index create those stash files. It is unrelated to the occurrence of duplicate events. The allocation of all sources is equal &lt;STRONG&gt;(25%)&lt;/STRONG&gt; , as you can see below. Is that correct ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1711961995247.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29993iE35441E290BE8B44/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1711961995247.png" alt="uagraw01_0-1711961995247.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 09:00:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682590#M19034</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-04-01T09:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple stats file from summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682596#M19036</link>
      <description>&lt;P&gt;These are consistent with the info_search_time graphic you shared earlier - is that what you are asking?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 09:29:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682596#M19036</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-04-01T09:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple stats file from summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682600#M19037</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp; I think this is the best suitable answer for my question as you posted earlier.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;it looks like the reports that were run on Feb 29th were done manually / ad hoc to back-fill the summary index for the earlier weeks before the schedule was set up and running correctly."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Apr 2024 09:45:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Multiple-stats-file-from-summary-index/m-p/682600#M19037</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-04-01T09:45:10Z</dc:date>
    </item>
  </channel>
</rss>

