<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Summary index issue to collect the data in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696573#M12614</link>
    <description>&lt;P&gt;So this is the reason why you are missing summary data. There could be a number of reasons for this difference.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;It could be that there is a delay in your infrastructure such that it takes a long time between the event being written to the log which is being ingested&lt;/LI&gt;&lt;LI&gt;It could be that the application is writing events with an event time which is many hours prior to the time it is written to the log&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;You should investigate this. If this is not something that can be fixed, then you could look at your summary index population searches to take these delays into account e.g. running "back fill" search that populate your summary index with these "delayed" events. You would need to be careful about "double-counting" events which have already been included in earlier populations of the summary index&lt;/P&gt;</description>
    <pubDate>Sat, 17 Aug 2024 11:33:21 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2024-08-17T11:33:21Z</dc:date>
    <item>
      <title>Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696534#M12606</link>
      <description>&lt;P class="lia-indent-padding-left-30px"&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello Splunkers!!&lt;/P&gt;&lt;P&gt;As per the below screenshot, you can see jobs are running fine. But events are not collecting into summary index. Please help me to suggest some potential reason and fixes&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1723834520966.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32268iF943880A19545E99/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1723834520966.png" alt="uagraw01_0-1723834520966.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scheduled search with push data to summary index.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1723834319806.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32267i4FB0E7AD10291C2E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1723834319806.png" alt="uagraw01_0-1723834319806.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 18:55:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696534#M12606</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-08-16T18:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696541#M12607</link>
      <description>&lt;P&gt;And how did you determine that the events are not collected? The typical issue with events which seem to be not collected (when the status does show returned events which should have been collected) is when there is something wrong with timestamps so that the events are collected and indexed but are put somewhere (or rather somewhen ;-)) else than you expect them to be.&lt;/P&gt;&lt;P&gt;Check your | tstats count on summary index over all time before and after you run the collecting search. This will tell you if your index grows.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 19:37:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696541#M12607</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-16T19:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696563#M12608</link>
      <description>&lt;P&gt;&lt;BR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;As per the below screenshot I can see huge delays in the indexing. So is this the cause that data is not visible on time.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;What actions I need to perform for summary index?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1723883013137.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32272i5E244BDDE25F7B19/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1723883013137.png" alt="uagraw01_0-1723883013137.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 08:26:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696563#M12608</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-08-17T08:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696564#M12609</link>
      <description>&lt;P&gt;There's nothing wrong with the index itself. Leave it alone &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Depending on your data, your search and your collect command syntax that can actually be an OK result. Impossible to say without knowing your usecase and those details.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 09:03:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696564#M12609</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-17T09:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696565#M12610</link>
      <description>&lt;P&gt;What delays do you get for your source data?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 09:06:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696565#M12610</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-17T09:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696568#M12611</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see there is a huge delayed in hours in the source data which fills the summary index is around 8.67 hours.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Green arrows:&lt;/STRONG&gt; To showcase the index and event time&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1723887534454.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32273iAE2B99805AB0455A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1723887534454.png" alt="uagraw01_0-1723887534454.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Below is the attributes I am using in props.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;DATETIME_CONFIG =&lt;BR /&gt;KV_MODE = xml&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;CHARSET = UTF-8&lt;BR /&gt;LINE_BREAKER = &amp;lt;\/eqtext:EquipmentEvent&amp;gt;()&lt;BR /&gt;crcSalt = &amp;lt;SOURCE&amp;gt;&lt;BR /&gt;NO_BINARY_CHECK = true&lt;BR /&gt;SHOULD_LINEMERGE = false&lt;BR /&gt;MAX_TIMESTAMP_LOOKAHEAD = 754&lt;BR /&gt;TIME_FORMAT = %Y-%m-%dT%H:%M:%S.%3QZ&lt;BR /&gt;TIME_PREFIX = \&amp;lt;\/State\&amp;gt;\&amp;lt;eqtext\:EventTime\&amp;gt;&lt;BR /&gt;SEDCMD-first = s/^.*&amp;lt;eqtext:EquipmentEvent/&amp;lt;eqtext:EquipmentEvent/g&lt;BR /&gt;category = Custom&lt;BR /&gt;pulldown_type = true&lt;BR /&gt;TZ = UTC&lt;/P&gt;&lt;P&gt;=====================================&lt;/P&gt;&lt;P&gt;Sample logs I am attaching below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;lt;eqtext:EquipmentEvent xmlns:eqtext="&lt;A href="http://Asas.com/FM/EqtEvent/EqtEventExtTypes/V1/1/5" target="_blank" rel="noopener"&gt;http://Asas.com/FM/EqtEvent/EqtEventExtTypes/V1/1/5&lt;/A&gt;" xmlns:sbt="&lt;A href="http://Asas.com/FM/Common/Services/ServicesBaseTypes/V1/8/4" target="_blank" rel="noopener"&gt;http://Asas.com/FM/Common/Services/ServicesBaseTypes/V1/8/4&lt;/A&gt;" xmlns:eqtexo="&lt;A href="http://Asas.com/FM/EqtEvent/EqtEventExtOut/V1/1/5" target="_blank" rel="noopener"&gt;http://Asas.com/FM/EqtEvent/EqtEventExtOut/V1/1/5&lt;/A&gt;"&amp;gt;&amp;lt;eqtext:ID&amp;gt;&amp;lt;eqtext:Location&amp;gt;&amp;lt;eqtext:PhysicalLocation&amp;gt;&amp;lt;AreaID&amp;gt;7073&amp;lt;/AreaID&amp;gt;&amp;lt;ZoneID&amp;gt;33&amp;lt;/ZoneID&amp;gt;&amp;lt;EquipmentID&amp;gt;81&amp;lt;/EquipmentID&amp;gt;&amp;lt;ElementID&amp;gt;0&amp;lt;/ElementID&amp;gt;&amp;lt;/eqtext:PhysicalLocation&amp;gt;&amp;lt;/eqtext:Location&amp;gt;&amp;lt;eqtext:Description&amp;gt; Applicator tamper is jammed&amp;lt;/eqtext:Description&amp;gt;&amp;lt;eqtext:MIS_Address&amp;gt;0.1&amp;lt;/eqtext:MIS_Address&amp;gt;&amp;lt;/eqtext:ID&amp;gt;&amp;lt;eqtext:Detail&amp;gt;&amp;lt;State&amp;gt;WENT_OUT&amp;lt;/State&amp;gt;&amp;lt;eqtext:EventTime&amp;gt;2024-08-16T12:14:24.843Z&amp;lt;/eqtext:EventTime&amp;gt;&amp;lt;eqtext:MsgNr&amp;gt;6232609270406364028&amp;lt;/eqtext:MsgNr&amp;gt;&amp;lt;Severity&amp;gt;LOW&amp;lt;/Severity&amp;gt;&amp;lt;eqtext:OperatorID&amp;gt;WALVAU-SCADA-1&amp;lt;/eqtext:OperatorID&amp;gt;&amp;lt;ErrorType&amp;gt;TECHNICAL&amp;lt;/ErrorType&amp;gt;&amp;lt;/eqtext:Detail&amp;gt;&amp;lt;/eqtext:EquipmentEvent&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;eqtext:EquipmentEvent xmlns:eqtext="&lt;A href="http://Asas.com/FM/EqtEvent/EqtEventExtTypes/V1/1/5" target="_blank" rel="noopener"&gt;http://Asas.com/FM/EqtEvent/EqtEventExtTypes/V1/1/5&lt;/A&gt;" xmlns:sbt="&lt;A href="http://Asas.com/FM/Common/Services/ServicesBaseTypes/V1/8/4" target="_blank" rel="noopener"&gt;http://Asas.com/FM/Common/Services/ServicesBaseTypes/V1/8/4&lt;/A&gt;" xmlns:eqtexo="&lt;A href="http://Asas.com/FM/EqtEvent/EqtEventExtOut/V1/1/5" target="_blank" rel="noopener"&gt;http://Asas.com/FM/EqtEvent/EqtEventExtOut/V1/1/5&lt;/A&gt;"&amp;gt;&amp;lt;eqtext:ID&amp;gt;&amp;lt;eqtext:Location&amp;gt;&amp;lt;eqtext:PhysicalLocation&amp;gt;&amp;lt;AreaID&amp;gt;7073&amp;lt;/AreaID&amp;gt;&amp;lt;ZoneID&amp;gt;33&amp;lt;/ZoneID&amp;gt;&amp;lt;EquipmentID&amp;gt;81&amp;lt;/EquipmentID&amp;gt;&amp;lt;ElementID&amp;gt;0&amp;lt;/ElementID&amp;gt;&amp;lt;/eqtext:PhysicalLocation&amp;gt;&amp;lt;/eqtext:Location&amp;gt;&amp;lt;eqtext:Description&amp;gt; Applicator tamper is jammed&amp;lt;/eqtext:Description&amp;gt;&amp;lt;eqtext:MIS_Address&amp;gt;0.1&amp;lt;/eqtext:MIS_Address&amp;gt;&amp;lt;/eqtext:ID&amp;gt;&amp;lt;eqtext:Detail&amp;gt;&amp;lt;State&amp;gt;ACK_BY_SYSTEM&amp;lt;/State&amp;gt;&amp;lt;eqtext:EventTime&amp;gt;2024-08-16T12:14:24.843Z&amp;lt;/eqtext:EventTime&amp;gt;&amp;lt;eqtext:MsgNr&amp;gt;6232609270406364028&amp;lt;/eqtext:MsgNr&amp;gt;&amp;lt;Severity&amp;gt;LOW&amp;lt;/Severity&amp;gt;&amp;lt;eqtext:OperatorID&amp;gt;WALVAU-SCADA-1&amp;lt;/eqtext:OperatorID&amp;gt;&amp;lt;ErrorType&amp;gt;TECHNICAL&amp;lt;/ErrorType&amp;gt;&amp;lt;/eqtext:Detail&amp;gt;&amp;lt;/eqtext:EquipmentEvent&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me what I can do fix it.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 09:48:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696568#M12611</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-08-17T09:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696569#M12612</link>
      <description>&lt;P&gt;The Time column shown is the local time for the UTC time in the event which appears to be 4 hours different. This does not show you the index time of the event, merely how the time field has been interpreted from the event at ingestion time.&lt;/P&gt;&lt;P&gt;You need to do the same calculation you did for the summary index i.e. _indextime - _time to find out the lag between the event time and the index time to see if this is the "source" of your "delay" - note this is not really the true source of the delay, if it is significant e.g. over 1hr 45 minutes, this could be the reason why you are not getting the events into your summary index.&lt;/P&gt;&lt;P&gt;For example, if you have an event with a time of 01:15am, it would have to have been indexed by 02:45am in order for it to appear in the report which is populating the summary index for 01:00am to 02:00am&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 11:01:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696569#M12612</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-17T11:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696572#M12613</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I ran query for on the source data which fills the summary index and below is the results.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1723893777153.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32274i3512CF1C1FE3BA3D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1723893777153.png" alt="uagraw01_0-1723893777153.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 11:24:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696572#M12613</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-08-17T11:24:17Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696573#M12614</link>
      <description>&lt;P&gt;So this is the reason why you are missing summary data. There could be a number of reasons for this difference.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;It could be that there is a delay in your infrastructure such that it takes a long time between the event being written to the log which is being ingested&lt;/LI&gt;&lt;LI&gt;It could be that the application is writing events with an event time which is many hours prior to the time it is written to the log&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;You should investigate this. If this is not something that can be fixed, then you could look at your summary index population searches to take these delays into account e.g. running "back fill" search that populate your summary index with these "delayed" events. You would need to be careful about "double-counting" events which have already been included in earlier populations of the summary index&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 11:33:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696573#M12614</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-17T11:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696577#M12615</link>
      <description>&lt;P&gt;The source itself might be simply misconfigured and using wrong timezone. If it's using time sync of some kind it shouldn't happen when the time is reported in UTC but if the time was manually set using&amp;nbsp; wrong timezone it will be reported as wrong timestamp.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 12:41:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696577#M12615</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-17T12:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696579#M12616</link>
      <description>&lt;P&gt;Here I am taking the TIME_FORMAT in props.conf from the eventtime field present in raw data (&lt;SPAN&gt;Toronto’s time zone is EST (UTC -5:00).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Is there any changes here I need to change.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 14:50:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696579#M12616</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-08-17T14:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696580#M12617</link>
      <description>&lt;P&gt;The time format actually seems to match your event. But the question is whether the event itself contains right information. You'd have to check the source system's configuration for that.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 15:19:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696580#M12617</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-17T15:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696606#M12618</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have removed so many duplicates events. Because of it &lt;STRONG&gt;delta_time&lt;/STRONG&gt; difference is decreased to 1.9 hours as compared to yesterday. Is the duplicate events also be the potential cause ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1723956821721.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/32278iE3A49C7D1EEEDBA1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1723956821721.png" alt="uagraw01_0-1723956821721.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 05:05:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696606#M12618</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-08-18T05:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696616#M12619</link>
      <description>&lt;P&gt;How is it possible for me to tell ? You haven't explained which duplicate events you have removed, nor how you removed them. If you can show that the 10 hour delay that you are seeing in your calculation is caused by duplicate events (which is possible if you have collected events for those time periods over 10 hours after their timestamps), then removing these duplicate events would affect your delay statistic.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 08:50:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696616#M12619</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2024-08-18T08:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696623#M12620</link>
      <description>&lt;P&gt;OK. It's starting to get a bit silly. A community is meant to be a help by users for other users. Help in learning the platform and what it can do, checking if your train of thought is correct and so on. It is _not_ meant as a free support service. And you're trying to do just that - get your problem solved without trying to understand the underlying issue and providing almost no information about it.&lt;/P&gt;&lt;P&gt;You obviously have _some_ problem with your data ingestion process. What it is? We don't know. It's something that should be examined on your site locally by someone who can verify the data as it is ingested into Splunk, who can check the settings across your Splunk infrastructure and who can talk with administrators of your sources to verify the settings on their side and what and how they produce the data you're ingesting into Splunk.&lt;/P&gt;&lt;P&gt;This is not something you can do by asking single questions on Answers without any significant effort on your side (true, sometimes Answers can be helpful in diagnostics when the asking person does quite a lot of work on their own and only needs some gentle hints now and then). This is something a skilled Splunk engineer would probably diagnose in a relatively short time compared to ping-ponging scraps of information to Answers and back.&lt;/P&gt;&lt;P&gt;People on Answers are volunteers who use their spare time to help others. But that doesn't mean that they are free support service. You want some effort from them - show some serious effort on your side as well. Make the problem interesting, not frustrating because you're asking about stuff they have no idea of knowing because it's your internal information.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 09:22:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696623#M12620</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-18T09:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696633#M12621</link>
      <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;Thanks for your help so far. I have received this unpleasant response 2 times from you .Let me tell you that I do not post queries to waste anyone's time. If you don't want the response on my queries then please don't respond. But this kind of reply from you makes me feel more embarrassed that I am really wasting people's time in Splunk Answers platform. You are not working for me and I am not working for you. According to me, this is a platform where I can ask my query, whoever wants to respond to it should do so.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 10:59:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696633#M12621</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-08-18T10:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696636#M12622</link>
      <description>&lt;P&gt;I'm not saying you're wasting people's time deliberately. It's just that this is one of those cases where someone (in this case you) asks one thing without giving much background info, then it leads to more and more problems and issues the poster is either unaware of or is not willing to share and only keeps insisting on providing a solution based on a very small piece of the actual information needed for such troubleshooting.&lt;/P&gt;&lt;P&gt;I didn't mean to be rude against you but you're repeatedly asking "how to fix that" without actually digging into what we're suggesting. You do some random things (like "removing duplicates" whatever that should mean) instead of really investigating the issue. And then ask "is this the potential cause".&lt;/P&gt;&lt;P&gt;We're trying to help here but it quickly gets frustrating. I understand that people have different skill levels and knowledge but you're doing completely different things that are suggested to you and end up asking "why is it so?". That's why I'm saying that this is something you normally pay people for - they come to you, they do things _for you_ and everybody's happy. I cannot say for others but I'm usually trying to be helpful and friendly and if you check other threads when I'm active I take my time to explain my answers so that people not only know _what_ to do but also _why_ it works but in this case... well, if we're telling you "check your f...ascinating sources" then please do check your sources. You can't fix reality - if the sources do send you wrong data, you'll end up with wrong data. No amount of "removing duplicates" will fix that. So don't take it personally, because I don't know you and I don't know who you are. All I know is that this thread as it is leads nowhere for now. That's why I wrote that it's frustrating and it's all getting silly.&lt;/P&gt;&lt;P&gt;Of course we could point you to the docs and tell you - here's what should be configured, apparently something is not done properly (most of the time the answer really _is_ in the docs or your config/data) but we're not doing that. But in return we'd (ok I'd) expect some serious effort on your side. Not some random bits and pieces, jumping from one index to another and dropping some screenshots which tell us absolutely nothing. Honestly, I find it more frustrating than if you simply asked "ok, guys, I have no idea what you're talking about, can you explain that?".&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 14:34:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696636#M12622</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-18T14:34:58Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696638#M12623</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that my way of asking queries is wrong in bits and pieces and a master like you did not like it. I value the Splunk Answers platform and I am also familiar with the contributions you have been making to users on the Splunk Answers platform over the years.&lt;/P&gt;&lt;P&gt;You could have simply told me you don't want to respond on my half of the details post. I have been posting at least 100 + queries on Splunk answers throughout my Splunk career and I have not received a reply like today. You are such a valuable member of the Splunk trust, your reply has shattered my confidence.&lt;/P&gt;&lt;P&gt;By writing like this type of unpleasant reply you diverted the attention of other users and experts who want to reply me and as a result essence of the query post is lost. I have seen your behaviour from my last two posts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I exit this thread chat while maintaining the decorum of the Splunk Answers platform.&lt;/P&gt;&lt;P&gt;Thanks for all the help.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 15:34:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696638#M12623</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2024-08-18T15:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index issue to collect the data</title>
      <link>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696640#M12624</link>
      <description>&lt;P&gt;OK. If you found a way to feel offended, well that was not my intention. I just wanted to point out that what you were doing in this thread was counterproductive and it was indeed simply impossible to help you this way. Want to help us help you? Fine, do so - check your sources and verify what was already suggested in this thread. Want to just take offense? Well, I'm trully sorry to hear that because we're really trying to create an overally friendly atmosphere here. And again - it was not my intention to make you personally feel bad. The intention was to point out that doing random things and just "splashing" random bits of information you will not get a reasonable answer because it's simply impossible. That's all. Hope you still have fun on Answers.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Aug 2024 16:46:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Summary-index-issue-to-collect-the-data/m-p/696640#M12624</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-08-18T16:46:32Z</dc:date>
    </item>
  </channel>
</rss>

