<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266443#M10156</link>
    <description>&lt;P&gt;What's the logic behind having this discrepancy?  I don't administer the application so I don't yet know what the retention period is, but, why would someone want the Data Summary to continue to show results for data which is no longer present for the next X days/weeks/months?&lt;/P&gt;</description>
    <pubDate>Thu, 21 Apr 2016 12:41:23 GMT</pubDate>
    <dc:creator>lib_systems</dc:creator>
    <dc:date>2016-04-21T12:41:23Z</dc:date>
    <item>
      <title>Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266423#M10136</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;We have weird behavior, in the Data Summary Screen on the Search Head, we see a Host reporting events, when clic on the host searching for the details, the Search Head shows 0 results&lt;/P&gt;

&lt;P&gt;This is happening only with 1 host, other hosts from the same index and same sourcetype didn't present the same issue.&lt;/P&gt;

&lt;P&gt;Any Ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 21:58:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266423#M10136</guid>
      <dc:creator>israelgutierrez</dc:creator>
      <dc:date>2016-03-30T21:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266424#M10137</link>
      <description>&lt;P&gt;Have there been calls to the &lt;CODE&gt;delete&lt;/CODE&gt; command?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 22:05:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266424#M10137</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-03-30T22:05:42Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266425#M10138</link>
      <description>&lt;P&gt;No, no one have those privileges &lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 22:09:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266425#M10138</guid>
      <dc:creator>israelgutierrez</dc:creator>
      <dc:date>2016-03-30T22:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266426#M10139</link>
      <description>&lt;P&gt;Okay... made sure the search runs over a sufficiently large time range?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 22:11:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266426#M10139</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-03-30T22:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266427#M10140</link>
      <description>&lt;P&gt;The Summary screen shows Last Update 3-30-16 2:34:26.000 PM&lt;/P&gt;

&lt;P&gt;But searching for that Host on Today, shows 0 results&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 22:17:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266427#M10140</guid>
      <dc:creator>israelgutierrez</dc:creator>
      <dc:date>2016-03-30T22:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266428#M10141</link>
      <description>&lt;P&gt;Search over all time - could be old data / misrecognized timestamp.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 22:19:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266428#M10141</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-03-30T22:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266429#M10142</link>
      <description>&lt;P&gt;Yeah, last log received - as in time it was indexed. The timestamp extracted from the events may be different.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 22:25:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266429#M10142</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-03-30T22:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266430#M10143</link>
      <description>&lt;P&gt;Ok, for that Got It, after a couple of reviews we are seeing that the _time of the log and the _indexed time are consistent so we are extracting the time correctly &lt;/P&gt;

&lt;P&gt;But Sadly we know that host it have events today,  and in the "All time search" the logs for today doesn't shows, but the Data Summary it shows updates&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 22:46:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266430#M10143</guid>
      <dc:creator>israelgutierrez</dc:creator>
      <dc:date>2016-03-30T22:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266431#M10144</link>
      <description>&lt;P&gt;Hmm... to drill deeper, run this over today:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| tstats count where index=* by index host sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 30 Mar 2016 22:47:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266431#M10144</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-03-30T22:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266432#M10145</link>
      <description>&lt;P&gt;Doing that search the host we are looking for didn't appear&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 22:59:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266432#M10145</guid>
      <dc:creator>israelgutierrez</dc:creator>
      <dc:date>2016-03-30T22:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266433#M10146</link>
      <description>&lt;P&gt;Okay, this?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| metadata type=hosts index=*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 30 Mar 2016 23:04:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266433#M10146</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-03-30T23:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266434#M10147</link>
      <description>&lt;P&gt;Yes, on that one the host appears with 766 Events&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 23:11:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266434#M10147</guid>
      <dc:creator>israelgutierrez</dc:creator>
      <dc:date>2016-03-30T23:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266435#M10148</link>
      <description>&lt;P&gt;There should be three timestamps for that host, what are they?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 23:25:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266435#M10148</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-03-30T23:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266436#M10149</link>
      <description>&lt;P&gt;FirstTime&lt;BR /&gt;
30/3/2013 14:06:56 GMT-6:00&lt;/P&gt;

&lt;P&gt;LastTime&lt;BR /&gt;
30/3/2013 17:08:12 GMT-6:00&lt;/P&gt;

&lt;P&gt;RecentTime&lt;BR /&gt;
30/3/2016 17:08:27 GMT-6:00&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 23:43:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266436#M10149</guid>
      <dc:creator>israelgutierrez</dc:creator>
      <dc:date>2016-03-30T23:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266437#M10150</link>
      <description>&lt;P&gt;All your data is from 2013, so searching today won't find it.&lt;/P&gt;

&lt;P&gt;The &lt;CODE&gt;metadata&lt;/CODE&gt; command powering the data summary is a bit more lenient with time ranges so it finds those old events.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2016 23:45:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266437#M10150</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-03-30T23:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266438#M10151</link>
      <description>&lt;P&gt;Thanks, The type of log is different from the others and the time it was bad recognized&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2016 00:13:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266438#M10151</guid>
      <dc:creator>israelgutierrez</dc:creator>
      <dc:date>2016-03-31T00:13:07Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266439#M10152</link>
      <description>&lt;P&gt;I am experiencing the same issue as the original post, however, I have been issuing the delete command to remove test data, etc.  When I issue the delete command it confirms that the correct number of events have been deleted, yet days later the Data Summary still shows event counts for hosts which no longer have associated events indexed.  Please advise.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 01:56:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266439#M10152</guid>
      <dc:creator>lib_systems</dc:creator>
      <dc:date>2016-04-21T01:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266440#M10153</link>
      <description>&lt;P&gt;The data summary is not updated by the delete command. &lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 08:53:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266440#M10153</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-04-21T08:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266441#M10154</link>
      <description>&lt;P&gt;And so how does one update the Data Summary after using the delete command?  The documentation glosses over this point.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 12:31:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266441#M10154</guid>
      <dc:creator>lib_systems</dc:creator>
      <dc:date>2016-04-21T12:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Data Summary Report Events for a Host but searching the Host in the Shearch Head Doesn't Show Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266442#M10155</link>
      <description>&lt;P&gt;You don't. It updates itself when the bucket ages out. &lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 12:34:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Data-Summary-Report-Events-for-a-Host-but-searching-the-Host-in/m-p/266442#M10155</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2016-04-21T12:34:20Z</dc:date>
    </item>
  </channel>
</rss>

