<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: successful summary search but no data in the summary index in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/successful-summary-search-but-no-data-in-the-summary-index/m-p/54335#M529</link>
    <description>&lt;P&gt;The error means that the results file &lt;CODE&gt;/var/groupon/splunk/var/run/splunk/1354684647.1.tmp&lt;/CODE&gt; could not be moved into the spool directory &lt;CODE&gt;/var/groupon/splunk/var/spool/splunk&lt;/CODE&gt; which is where it would be picked up to be indexed, which has a sinkhole (delete after indexing) input set up.&lt;/P&gt;

&lt;P&gt;Double check the permissions of the folder &lt;CODE&gt;/var/groupon/splunk/var/spool/splunk&lt;/CODE&gt;. Is it on the same volume as the rest of Splunk or a different one? Are there any files in &lt;CODE&gt;/var/groupon/splunk/var/spool/splunk&lt;/CODE&gt;?&lt;/P&gt;</description>
    <pubDate>Wed, 05 Dec 2012 18:16:02 GMT</pubDate>
    <dc:creator>dart</dc:creator>
    <dc:date>2012-12-05T18:16:02Z</dc:date>
    <item>
      <title>successful summary search but no data in the summary index</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/successful-summary-search-but-no-data-in-the-summary-index/m-p/54334#M528</link>
      <description>&lt;P&gt;An hourly scheduled summary search finishes successfully:&lt;/P&gt;

&lt;P&gt;12-05-2012 05:17:27.966 +0000 INFO  SavedSplunker - savedsearch_id="nobody;XXX;Summary Gen", user="nobody", app="XXX", savedsearch_name="Summary Gen", status=success, digest_mode=1, scheduled_time=1354684620, dispatch_time=1354684644, run_time=3.788, result_count=18244, alert_actions="summary_index", sid="scheduler_&lt;EM&gt;nobody_ZW1haWxfbWV0cmljc19hcHA&lt;/EM&gt;_RMD59f64bf9adfa139f1_at_1354684620_60d34ceed7aa64ec", suppressed=0, thread_id="AlertNotifierWorker-0"&lt;/P&gt;

&lt;P&gt;search.log in the dispatch directory has this error&lt;BR /&gt;
12-05-2012 05:17:27.748 ERROR SummaryIndexProcessor - Error moving file '/var/groupon/splunk/var/run/splunk/1354684647.1.tmp' to '/var/groupon/splunk/var/spool/splunk/RMD59f64bf9adfa139f1_1502598233.stash_new'.&lt;/P&gt;

&lt;P&gt;As a result the data doesn't arrive in the summary index. Also interesting that the scheduled search is considered successful&lt;/P&gt;

&lt;P&gt;What does this error mean?  There is plenty of free disk space. &lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:54:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/successful-summary-search-but-no-data-in-the-summary-index/m-p/54334#M528</guid>
      <dc:creator>paranoid</dc:creator>
      <dc:date>2020-09-28T12:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: successful summary search but no data in the summary index</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/successful-summary-search-but-no-data-in-the-summary-index/m-p/54335#M529</link>
      <description>&lt;P&gt;The error means that the results file &lt;CODE&gt;/var/groupon/splunk/var/run/splunk/1354684647.1.tmp&lt;/CODE&gt; could not be moved into the spool directory &lt;CODE&gt;/var/groupon/splunk/var/spool/splunk&lt;/CODE&gt; which is where it would be picked up to be indexed, which has a sinkhole (delete after indexing) input set up.&lt;/P&gt;

&lt;P&gt;Double check the permissions of the folder &lt;CODE&gt;/var/groupon/splunk/var/spool/splunk&lt;/CODE&gt;. Is it on the same volume as the rest of Splunk or a different one? Are there any files in &lt;CODE&gt;/var/groupon/splunk/var/spool/splunk&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2012 18:16:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/successful-summary-search-but-no-data-in-the-summary-index/m-p/54335#M529</guid>
      <dc:creator>dart</dc:creator>
      <dc:date>2012-12-05T18:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: successful summary search but no data in the summary index</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/successful-summary-search-but-no-data-in-the-summary-index/m-p/54336#M530</link>
      <description>&lt;P&gt;The scheduled search works most of the time, so it's not permissions. /var/groupon/splunk/var/spool/splunk has quite a few files, will a name collision explain this?&lt;/P&gt;

&lt;P&gt;And then I guess the next question is, why are there so many files there? Files should only live there for the duration of indexing. Some files are fra mid November and we are early December now.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2012 18:33:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/successful-summary-search-but-no-data-in-the-summary-index/m-p/54336#M530</guid>
      <dc:creator>paranoid</dc:creator>
      <dc:date>2012-12-05T18:33:25Z</dc:date>
    </item>
  </channel>
</rss>

