<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic collect command generates multiple rows in summary index for single event in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/collect-command-generates-multiple-rows-in-summary-index-for/m-p/544862#M154288</link>
    <description>&lt;P&gt;I am using the collect statement to collect a single event to a summary index. When run as a search, it will generate a single row. When run as part of a hidden search in a dashboard, I get multiple repeated rows in the summary index.&lt;/P&gt;&lt;P&gt;If I show the hidden search in a table in the dashboard, I also get the many rows in the summary, but only one in the shown table in the dashboard.&lt;/P&gt;&lt;P&gt;The search is part of a hierarchy of base searches, so the search for the table itself that has the collect statement is one search and there are 5 base searches backing it up.&lt;/P&gt;&lt;P&gt;If I press the rerun search icon in the table, I get 8 rows in the summary, but I normally get 5 or 7.&lt;/P&gt;&lt;P&gt;Anyone know why this is?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Mar 2021 03:58:14 GMT</pubDate>
    <dc:creator>bowesmana</dc:creator>
    <dc:date>2021-03-23T03:58:14Z</dc:date>
    <item>
      <title>collect command generates multiple rows in summary index for single event</title>
      <link>https://community.splunk.com/t5/Splunk-Search/collect-command-generates-multiple-rows-in-summary-index-for/m-p/544862#M154288</link>
      <description>&lt;P&gt;I am using the collect statement to collect a single event to a summary index. When run as a search, it will generate a single row. When run as part of a hidden search in a dashboard, I get multiple repeated rows in the summary index.&lt;/P&gt;&lt;P&gt;If I show the hidden search in a table in the dashboard, I also get the many rows in the summary, but only one in the shown table in the dashboard.&lt;/P&gt;&lt;P&gt;The search is part of a hierarchy of base searches, so the search for the table itself that has the collect statement is one search and there are 5 base searches backing it up.&lt;/P&gt;&lt;P&gt;If I press the rerun search icon in the table, I get 8 rows in the summary, but I normally get 5 or 7.&lt;/P&gt;&lt;P&gt;Anyone know why this is?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 03:58:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/collect-command-generates-multiple-rows-in-summary-index-for/m-p/544862#M154288</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2021-03-23T03:58:14Z</dc:date>
    </item>
  </channel>
</rss>

