<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Why does Custom summary index gets refreshed data in drilldown mismatch? in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-does-Custom-summary-index-gets-refreshed-data-in-drilldown/m-p/658416#M54241</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I have custom summary index, which is having the required fields from many indexes in order to make a dashboard. The problem is when P2 in first panel shows a count of 36, we have a drilldown to these numbers so that, we can check more details to it, at that time, count mismatches, because, the custom summary index gets refreshed in 2mins, and dashboard takes time to load. Please let me know, how to fix this so that, in drilldown panel upon load, count should match the first panel.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Sep 2023 18:25:23 GMT</pubDate>
    <dc:creator>Jugabanhi</dc:creator>
    <dc:date>2023-09-22T18:25:23Z</dc:date>
    <item>
      <title>Why does Custom summary index gets refreshed data in drilldown mismatch?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-does-Custom-summary-index-gets-refreshed-data-in-drilldown/m-p/658416#M54241</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;I have custom summary index, which is having the required fields from many indexes in order to make a dashboard. The problem is when P2 in first panel shows a count of 36, we have a drilldown to these numbers so that, we can check more details to it, at that time, count mismatches, because, the custom summary index gets refreshed in 2mins, and dashboard takes time to load. Please let me know, how to fix this so that, in drilldown panel upon load, count should match the first panel.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 18:25:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-does-Custom-summary-index-gets-refreshed-data-in-drilldown/m-p/658416#M54241</guid>
      <dc:creator>Jugabanhi</dc:creator>
      <dc:date>2023-09-22T18:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Custom summary index gets refreshed data in drilldown mismatch</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-does-Custom-summary-index-gets-refreshed-data-in-drilldown/m-p/658432#M54245</link>
      <description>&lt;P&gt;Change the timerange of both panel to some historical time for which your summary index will have data. E.g. earliest=-24h latest=-2m@m. This way your summary will have some data summarized and your drilldown search will only look at raw data for summarized data time-range only.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Sep 2023 14:27:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-does-Custom-summary-index-gets-refreshed-data-in-drilldown/m-p/658432#M54245</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2023-09-22T14:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Why does Custom summary index gets refreshed data in drilldown mismatch?</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Why-does-Custom-summary-index-gets-refreshed-data-in-drilldown/m-p/658595#M54260</link>
      <description>&lt;P&gt;you mean, by giving earliest and latest in the query for both the panels? basically, the count is updated on drilldown from first panel, because the index gets refreshed.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Sep 2023 13:51:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Why-does-Custom-summary-index-gets-refreshed-data-in-drilldown/m-p/658595#M54260</guid>
      <dc:creator>Jugabanhi</dc:creator>
      <dc:date>2023-09-25T13:51:02Z</dc:date>
    </item>
  </channel>
</rss>

