<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Summary Index Producing Doubled Results in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23750#M174</link>
    <description>&lt;P&gt;What are the searches that you run to collect data in the summary index? And what the one used to check for double events? &lt;BR /&gt;
On a sidenote, it would be safer to set the interval of the saved searches to:  from: -5m@m to:@m&lt;/P&gt;</description>
    <pubDate>Thu, 02 Aug 2012 11:57:09 GMT</pubDate>
    <dc:creator>Paolo_Prigione</dc:creator>
    <dc:date>2012-08-02T11:57:09Z</dc:date>
    <item>
      <title>Summary Index Producing Doubled Results</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23749#M173</link>
      <description>&lt;P&gt;I've recently created a saved search to store items into a summary index.  It's scheduled to run every 5 minutes and searches with the parameters:&lt;/P&gt;

&lt;P&gt;Start time: -5m@m&lt;BR /&gt;
Finish time: now&lt;/P&gt;

&lt;P&gt;Thus, the results produced should be recording a chunk of events from a source index every 5 minutes and adding them to the summary index.  Also, just as an FYI, the source index just happens to only have 1 entry every 5 minutes.  So I'm expecting this one entry is found every 5 minutes and put into the summary index.&lt;/P&gt;

&lt;P&gt;However, instead, what I'm seeing is that my entries in the summary index are doubled!  Instead of that 1 entry every 5 minutes I'm expecting, what I find instead is &lt;STRONG&gt;2&lt;/STRONG&gt; entries every 5 minutes, which is the correct entry... just in there twice.&lt;/P&gt;

&lt;P&gt;I've even set the saved search to execute every 15 minutes instead, searching the source index with the time range of "-15m@m" to "now".  When I do this, the results are still doubled.  This ruled out any chances of an entry being doubled by being found on the edges of both time ranges.&lt;/P&gt;

&lt;P&gt;Also, someone else on my team has run a similar set up with a saved search running once every hour grabbing events from a source index.  Within that hour, there are many, many, many entries to be found.  But in the summary index, we find that every entry is in there exactly twice again.&lt;/P&gt;

&lt;P&gt;Has anyone else experienced this problem?  Am I setting this up incorrectly?  Thanks!&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;James&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 02 Aug 2012 01:12:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23749#M173</guid>
      <dc:creator>jchensor</dc:creator>
      <dc:date>2012-08-02T01:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index Producing Doubled Results</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23750#M174</link>
      <description>&lt;P&gt;What are the searches that you run to collect data in the summary index? And what the one used to check for double events? &lt;BR /&gt;
On a sidenote, it would be safer to set the interval of the saved searches to:  from: -5m@m to:@m&lt;/P&gt;</description>
      <pubDate>Thu, 02 Aug 2012 11:57:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23750#M174</guid>
      <dc:creator>Paolo_Prigione</dc:creator>
      <dc:date>2012-08-02T11:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index Producing Doubled Results</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23751#M175</link>
      <description>&lt;P&gt;I've added that information to the original post.  As for the interval part, I'll definitely switch it to "@m" from now on.  That's good advice, thanks.  I'll let you know if it causes any changes to the results.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;James&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 02 Aug 2012 18:45:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23751#M175</guid>
      <dc:creator>jchensor</dc:creator>
      <dc:date>2012-08-02T18:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index Producing Doubled Results</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23752#M176</link>
      <description>&lt;P&gt;Actually, for organization, I'm putting the search info here instead:&lt;/P&gt;

&lt;P&gt;Adding my saved search here.&lt;/P&gt;

&lt;P&gt;index=fooindex sourcetype=somesourcetype FIELD1="Value1" FIELD2="Value2" | stats avg(FIELD3) as FIELD4 by _time, FIELD1&lt;/P&gt;

&lt;P&gt;I then have it scheduled to run every 5 minutes and Summary Indexing is enabled and I've selected a summary index I'll call "summary-data".&lt;/P&gt;

&lt;P&gt;Then, when I search to see my results, all I do is run the search "index=summary-data" and see what pops up.  And this is where I see each of the results duplicated.&lt;/P&gt;

&lt;P&gt;Hope that helps a little.&lt;/P&gt;

&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2012 00:06:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23752#M176</guid>
      <dc:creator>jchensor</dc:creator>
      <dc:date>2012-08-03T00:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index Producing Doubled Results</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23753#M177</link>
      <description>&lt;P&gt;An interesting development: so currently, I have 4 Search Heads in my environment.  2 of them are older, running on Splunk 4.2.5, and two of them are new, running on 4.3.3.&lt;/P&gt;

&lt;P&gt;I set up the same saved searches and a local index on a 4.2.5 Search Head machine, and I'm NOT getting any duplicate events.  However, my teammate saw the duplicated entries on one of the 4.3.3 machines and I saw the duplicated entries on the OTHER 4.3.3 machine.  So either there's a bug in 4.3.3 or I did something wrong when I installed Splunk on the two new machines and have a setting set incorrectly.&lt;/P&gt;

&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2012 00:07:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23753#M177</guid>
      <dc:creator>jchensor</dc:creator>
      <dc:date>2012-08-03T00:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index Producing Doubled Results</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23754#M178</link>
      <description>&lt;P&gt;Latest development:&lt;/P&gt;

&lt;P&gt;My teammate checked the dispatch folder to find the actual results, and in the results.csv.gz files, the results are actually not duplicated! Each result is found only once.&lt;/P&gt;

&lt;P&gt;Also, we see these random entries in the summary index:&lt;/P&gt;

&lt;P&gt;---SPLUNK--- index="summary-data" source="SEARCH-NAME"&lt;/P&gt;

&lt;P&gt;The reason this sticks out to us is that, when we ran these searches on our older 4.2.5 Search Heads, these types of events were nowhere to be found.&lt;/P&gt;

&lt;P&gt;So for some reason, Splunk is displaying the entries twice.  So this appears to be a viewing problem, not an indexing one.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;James&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 03 Aug 2012 00:11:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23754#M178</guid>
      <dc:creator>jchensor</dc:creator>
      <dc:date>2012-08-03T00:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index Producing Doubled Results</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23755#M179</link>
      <description>&lt;P&gt;Also, in the entry above, the random entry is supposed to have three asterisks (*) before and after the word SPLUNK, but when I do that here, it bold faces and italicizes the word.  ^_^  So just pretend those dashes are asterisks.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Aug 2012 00:13:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23755#M179</guid>
      <dc:creator>jchensor</dc:creator>
      <dc:date>2012-08-03T00:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index Producing Doubled Results</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23756#M180</link>
      <description>&lt;P&gt;I'm having the same problem; no solution yet.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2012 20:27:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23756#M180</guid>
      <dc:creator>pheezy</dc:creator>
      <dc:date>2012-08-13T20:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index Producing Doubled Results</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23757#M181</link>
      <description>&lt;P&gt;the &lt;CODE&gt;xxx SPLUNK xxx&lt;/CODE&gt; header in the file is actually metadata you can put into any file. See &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/Assignmetadatatoeventsdynamically#Configure_a_single_input_file"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/Assignmetadatatoeventsdynamically#Configure_a_single_input_file&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;/kristian&lt;/P&gt;</description>
      <pubDate>Mon, 13 Aug 2012 20:49:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23757#M181</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-08-13T20:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index Producing Doubled Results</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23758#M182</link>
      <description>&lt;P&gt;I don't recommend this, but we have found an iffy workaround.  Perform at own risk.  ^_^&lt;/P&gt;

&lt;P&gt;My teammate experimented a bit and modified the inputs.conf in the etc/system/default folder (the path you are never supposed to alter).  Interestingly, she tried switching the monitoring of the stash files from "batch" to "monitor". So the sections that read:&lt;/P&gt;

&lt;P&gt;[batch://$SPLUNK_HOME/var/spool/splunk]&lt;BR /&gt;
move_policy = sinkhole&lt;BR /&gt;
crcSalt = &lt;SOURCE&gt;&lt;/SOURCE&gt;&lt;/P&gt;

&lt;P&gt;[batch://$SPLUNK_HOME/var/spool/splunk/...stash_new]&lt;BR /&gt;
queue = stashparsing&lt;BR /&gt;
sourcetype = stash_new&lt;BR /&gt;
move_policy = sinkhole&lt;BR /&gt;
crcSalt = &lt;SOURCE&gt;&lt;/SOURCE&gt;&lt;/P&gt;

&lt;P&gt;(continued in next post)&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:17:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23758#M182</guid>
      <dc:creator>jchensor</dc:creator>
      <dc:date>2020-09-28T12:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index Producing Doubled Results</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23759#M183</link>
      <description>&lt;P&gt;...were modified to look like this:&lt;/P&gt;

&lt;P&gt;#[batch://$SPLUNK_HOME/var/spool/splunk]&lt;BR /&gt;
 #move_policy = sinkhole&lt;BR /&gt;
 #crcSalt = &lt;SOURCE&gt;&lt;/SOURCE&gt;&lt;/P&gt;

&lt;P&gt;#[batch://$SPLUNK_HOME/var/spool/splunk/...stash_new]&lt;BR /&gt;
 [monitor://$SPLUNK_HOME/var/spool/splunk/...stash_new]&lt;BR /&gt;
 queue = stashparsing&lt;BR /&gt;
 sourcetype = stash_new&lt;BR /&gt;
 #move_policy = sinkhole&lt;BR /&gt;
 crcSalt = &lt;SOURCE&gt;&lt;/SOURCE&gt;&lt;/P&gt;

&lt;P&gt;After that change, everything has actually started WORKING properly! Those weird header lines that start with ---SPLUNK--- ... are no longer there, and events are only displaying once instead of being doubled. In other words, everything looks completely accurate.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:17:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23759#M183</guid>
      <dc:creator>jchensor</dc:creator>
      <dc:date>2020-09-28T12:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index Producing Doubled Results</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23760#M184</link>
      <description>&lt;P&gt;Obviously, this is not a solution we want to go with, as modifying those files is definitely NOT the right solution. But I figured it'd be interesting to note that we have come to a working solution by doing this and lets you move forward with any other forms of testing you wanted to do.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Aug 2012 01:55:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23760#M184</guid>
      <dc:creator>jchensor</dc:creator>
      <dc:date>2012-08-18T01:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index Producing Doubled Results</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23761#M185</link>
      <description>&lt;P&gt;Has anyone else seen this behavior? I'm having the same problem. Single search running every five minutes. I get double the number of entries in the summary_index.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2013 17:29:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-Producing-Doubled-Results/m-p/23761#M185</guid>
      <dc:creator>colinj</dc:creator>
      <dc:date>2013-06-10T17:29:32Z</dc:date>
    </item>
  </channel>
</rss>

