<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scheduled search for populating summary index ignores the last 30 seconds of events in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-search-for-populating-summary-index-ignores-the-last/m-p/543587#M153976</link>
    <description>&lt;P&gt;There's often (usually) a delay from when an event is generated and when it is searchable within Splunk.&amp;nbsp; That delay can exceed 30 seconds and is why many Enterprise Security searches use &lt;FONT face="courier new,courier"&gt;latest=-1m&lt;/FONT&gt; rather than &lt;FONT face="courier new,courier"&gt;latest=now&lt;/FONT&gt;.&lt;/P&gt;&lt;P&gt;There may be other explanations, like a &lt;FONT face="courier new,courier"&gt;transaction&lt;/FONT&gt; command discarding events because they aren't (yet) part of a complete transaction.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Mar 2021 20:30:36 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-03-12T20:30:36Z</dc:date>
    <item>
      <title>Scheduled search for populating summary index ignores the last 30 seconds of events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-search-for-populating-summary-index-ignores-the-last/m-p/543580#M153974</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I recently faced an issue when populating a summary index. I scheduled a saved search to run every hour (with the last 60 minutes time range) and populate a summary index. The search takes around 5 minutes every time to be completed. My problem is&amp;nbsp;that&amp;nbsp;&lt;SPAN&gt;every time this scheduled search runs to populate the index, events in the last 30 seconds of the time range will be discarded from the results by Splunk.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;For example, for&amp;nbsp;a one-hour time range like 9:00:00 to 10:00:00, the index is only populated with the events from 9:00:00 to 9:59:30. This issue caused some gaps and discrepancies in our index data.&amp;nbsp; Is there any way to solve this?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I searched a lot but couldn't find any answer &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 18:50:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Scheduled-search-for-populating-summary-index-ignores-the-last/m-p/543580#M153974</guid>
      <dc:creator>Sharzi</dc:creator>
      <dc:date>2021-03-12T18:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled search for populating summary index ignores the last 30 seconds of events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-search-for-populating-summary-index-ignores-the-last/m-p/543587#M153976</link>
      <description>&lt;P&gt;There's often (usually) a delay from when an event is generated and when it is searchable within Splunk.&amp;nbsp; That delay can exceed 30 seconds and is why many Enterprise Security searches use &lt;FONT face="courier new,courier"&gt;latest=-1m&lt;/FONT&gt; rather than &lt;FONT face="courier new,courier"&gt;latest=now&lt;/FONT&gt;.&lt;/P&gt;&lt;P&gt;There may be other explanations, like a &lt;FONT face="courier new,courier"&gt;transaction&lt;/FONT&gt; command discarding events because they aren't (yet) part of a complete transaction.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 20:30:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Scheduled-search-for-populating-summary-index-ignores-the-last/m-p/543587#M153976</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-12T20:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled search for populating summary index ignores the last 30 seconds of events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-search-for-populating-summary-index-ignores-the-last/m-p/543601#M153979</link>
      <description>&lt;P&gt;I usually schedule summary index updates at least 5 minutes past the hour for the previous hour, just to give the indexers time to do their work.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 22:36:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Scheduled-search-for-populating-summary-index-ignores-the-last/m-p/543601#M153979</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-03-12T22:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled search for populating summary index ignores the last 30 seconds of events</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Scheduled-search-for-populating-summary-index-ignores-the-last/m-p/543886#M154062</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;We don't have any transaction command in our search query, but as you said, the problem was "latest".&lt;/P&gt;&lt;P&gt;I changed the "latest" and now it is working fine! Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Mar 2021 15:47:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Scheduled-search-for-populating-summary-index-ignores-the-last/m-p/543886#M154062</guid>
      <dc:creator>Sharzi</dc:creator>
      <dc:date>2021-03-15T15:47:44Z</dc:date>
    </item>
  </channel>
</rss>

