<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk summary index in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669861#M229681</link>
    <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Let me understand correctly, if more than one source is generating that means, more than one summary index ? Multiple source “/var/spool*” &amp;nbsp;file generation on the same time frame means ?&lt;/P&gt;</description>
    <pubDate>Mon, 27 Nov 2023 15:04:02 GMT</pubDate>
    <dc:creator>uagraw01</dc:creator>
    <dc:date>2023-11-27T15:04:02Z</dc:date>
    <item>
      <title>splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669820#M229666</link>
      <description>&lt;P&gt;In the below screenshot, we can see that from November 6th onwards, there are three sources generated in Splunk; it shows only one "&lt;SPAN&gt;File Collector: DepTrayCaseQty." Splunk created unnecessary two other sources. Because of the creation of two other sources, unwanted duplicate events were also generated. "D:\Splunk\var\spool\splunk\adb0f8d721bf93e3_events.stash_new" and "D:\Splunk\var\spool\splunk\d0d3783e41cf130c_events.stash_new" . Please guide us on how I can fix this issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1701087856173.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28247iAB33D75ED306FE4B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1701087856173.png" alt="uagraw01_0-1701087856173.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My assumption :&lt;/STRONG&gt; Is collect command is not working fine?&amp;nbsp;How to prevent both of those sources from being ingested into Splunk ?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 12:31:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669820#M229666</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2023-11-27T12:31:39Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669835#M229670</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;from November 6th onwards" begs the question, what changed in your environment on 6th November?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 13:17:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669835#M229670</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-27T13:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669836#M229671</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Number of events are thripled. As well as duplicated data ingested in splunk&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 13:25:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669836#M229671</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2023-11-27T13:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669839#M229673</link>
      <description>&lt;P&gt;I assume by that you mean there are two extra reports adding to the summary index? So, what else in your environment changed (which may have impacted the summary index)?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 13:24:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669839#M229673</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-27T13:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669850#M229677</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;No only one report Triggering the events&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 14:10:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669850#M229677</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2023-11-27T14:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669852#M229678</link>
      <description>&lt;P&gt;When did the report change? What does search does the current report use? What search did the report use prior to 6th November?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 14:12:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669852#M229678</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-27T14:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669853#M229679</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Can I check those details in _audit index ?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 14:17:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669853#M229679</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2023-11-27T14:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669856#M229680</link>
      <description>&lt;P&gt;It is certainly worth looking&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 14:38:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669856#M229680</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-27T14:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669861#M229681</link>
      <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Let me understand correctly, if more than one source is generating that means, more than one summary index ? Multiple source “/var/spool*” &amp;nbsp;file generation on the same time frame means ?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 15:04:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669861#M229681</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2023-11-27T15:04:02Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669870#M229684</link>
      <description>&lt;P&gt;summary is the default index for summaries but you can collect to different indexes. I can't tell from your screenshot whether these are for the same index or not.&lt;/P&gt;&lt;P&gt;Perhaps you should collect additional information about these sources e.g. exactly when did they update, what other fields are in the summary events, etc.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 15:40:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669870#M229684</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-27T15:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669875#M229686</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below are screenshot in which you can see from 6th of November we are receiving 3 sources. and before that the source was only one.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1701101901925.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28255i20C32A21C07B7137/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1701101901925.png" alt="uagraw01_0-1701101901925.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 16:19:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669875#M229686</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2023-11-27T16:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669878#M229687</link>
      <description>&lt;P&gt;Rather than pasting pictures, please paste 3 "duplicated" raw events into a code block &amp;lt;/&amp;gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 16:34:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669878#M229687</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-27T16:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669879#M229688</link>
      <description>&lt;LI-CODE lang="markup"&gt;11/06/2023 23:57:02 +1100, info_min_time=1699189200.000, info_max_time=1700571600.000, info_search_time=1700625838.094, foo=3, Mixed=0, CaseQty=64, OrderId=52128969634, TrayQty=35, Location="DEP/AutoDep03", Dimension=2, TrayError=3, OrientationError=1, ProtrusionError=0, CaseTypeId=6210, WidthError=2, reporttype=DepTrayCaseQty, OffCentreError=0, HeightError=0, LengthError=0, PalletLayers=4
OrderId = 52128969634host = MSRDC-BPIsource = D:\Splunk\var\spool\splunk\d0d3783e41cf130c_events.stash_newsourcetype = stash

=====================================================================

11/06/2023 23:57:02 +1100, search_name="File Collector: DepTrayCaseQty", search_now=1699279200.000, info_min_time=1699189200.000, info_max_time=1699275600.000, info_search_time=1699279202.226, foo=2, Mixed=0, CaseQty=29, OrderId=52128969634, TrayQty=17, Location="DEP/AutoDep03", Dimension=2, TrayError=2, OrientationError=0, ProtrusionError=0, CaseTypeId=6210, WidthError=2, reporttype=DepTrayCaseQty, OffCentreError=0, HeightError=0, LengthError=0, PalletLayers=4
OrderId = 52128969634host = MSRDC-BPIsource = File Collector: DepTrayCaseQtysourcetype = stash

=================================================================

11/06/2023 23:57:02 +1100, info_min_time=1699189200.000, info_max_time=1700398800.000, info_search_time=1700618994.511, foo=3, Mixed=0, CaseQty=64, OrderId=52128969634, TrayQty=35, Location="DEP/AutoDep03", Dimension=2, TrayError=3, OrientationError=1, ProtrusionError=0, CaseTypeId=6210, WidthError=2, reporttype=DepTrayCaseQty, OffCentreError=0, HeightError=0, LengthError=0, PalletLayers=4
OrderId = 52128969634host = MSRDC-BPIsource = D:\Splunk\var\spool\splunk\adb0f8d721bf93e3_events.stash_newsourcetype = stash&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 27 Nov 2023 16:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669879#M229688</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2023-11-27T16:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669889#M229692</link>
      <description>&lt;P&gt;Looking at the info times show that the events were added by different searches&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ITWhisperer_0-1701104306326.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28256iCBD52C6558D80AFF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ITWhisperer_0-1701104306326.png" alt="ITWhisperer_0-1701104306326.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;These appear to been executed on 22nd, with different time spans, 5th - 19th and 5th - 21st. These are the searches which have duplicated your events.&lt;/P&gt;&lt;P&gt;I did a BSides presentation a year or so ago about making summary index reports idempotent to avoid duplicate entries.&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=nYSikXNkXdE" target="_blank"&gt;Summary Index Idempotency - Chris Kaye - YouTube&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 17:03:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669889#M229692</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-27T17:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669905#M229702</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;Thanks, for sharing that valuable video. I have question, consider my below search which I am using to append the result in summary index. But here I am not using any subsearches, so where I can use your suggested workaround here ?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=ABC (sourcetype=DepTsuEventTrackingUpdate DepTsuEventTrackingUpdate.LocationQualifiedName=Tray* DepTsuEventTrackingUpdate.TsuSuspect.TsuSuspectReason!=null AND DepTsuEventTrackingUpdate.TsuSuspect.TsuSuspectReason!="TsuUnknownContent") OR (sourcetype=DepTsuEventContentMove) 
| foreach *.OrderId 
    [| eval OrderId=coalesce('OrderId','&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;')] 
| replace ProtrusionFront with Protrusion , ProtrusionBack with Protrusion , ProtrusionLeft with Protrusion , ProtrusionRight with Protrusion , ProtrusionTop with Protrusion 
| rename DepTsuEventTrackingUpdate.TsuSuspect.CheckResult.CheckType as Error DepTsuEventTrackingUpdate.TsuSuspect.TsuSuspectReason as TsuSuspectReason DepTsuEventContentMove.SenderFmInstanceName as Location DepTsuEventTrackingUpdate.TsuId as TsuId DepTsuEventContentMove.TsuContent.Quantity as Quantity DepTsuEventContentMove.LocationQualifiedName as TrayLoad DepTsuEventContentMove.TsuContent.CaseTypeId as CaseTypeId
| eval OrientationError=if(Error="Orientation","1","0") , ProtrusionError=if(Error="Protrusion","1","0") , LengthError=if(Error="Length","1","0") , WidthError=if(Error="Width","1","0") , HeightError=if(Error="Height","1","0") , OffCentreError=if(Error="OffCentre","1","0") 
| eval DimensionError=if(LengthError&amp;gt;0 OR WidthError&amp;gt;0 OR HeightError&amp;gt;0, "1","0") 
| eval ErrorQty=(OrientationError+ProtrusionError+DimensionError+OffCentreError) , TrayError=(OrientationError+ProtrusionError+LengthError+WidthError+HeightError+OffCentreError) , TrayError=if(TrayError&amp;gt;0,"1",null) 
| eval Dimension=if(DimensionError&amp;gt;0 AND ErrorQty="1" ,"1","0") , Orientation=if(OrientationError="1" AND ErrorQty="1","1","0") , Protrusion=if(ProtrusionError="1" AND ErrorQty="1","1","0") , Length=if(LengthError="1" AND ErrorQty="1","1","0") , Width=if(WidthError="1" AND ErrorQty="1","1","0") , Height=if(HeightError="1" AND ErrorQty="1","1","0") , OffCentre=if(OffCentreError="1" AND ErrorQty="1","1","0") , Mixed=if(Dimension="0" AND ErrorQty&amp;gt;1,"1","0") 
| eval Layer=if(TrayLoad="PalletInPosition","1",null) , CaseQty=if(TrayLoad="TrayLoad1" OR TrayLoad="TrayLoad2",Quantity,null) , Tray=if(TrayLoad="TrayLoad1" OR TrayLoad="TrayLoad2","1",null) 
| stats min(_time) as _time values(Location) as Location sum(Layer) as PalletLayers sum(Tray) as TrayQty sum(CaseQty) as CaseQty sum(TrayError) as TrayError sum(Orientation) as OrientationError sum(Length) as LengthError sum(Width) as WidthError sum(Height) as HeightError sum(Protrusion) as ProtrusionError sum(OffCentre) as OffCentreError sum(Dimension) as Dimension sum(Mixed) as Mixed values(CaseTypeId) as CaseTypeId by OrderId 
| eval reporttype="DepTrayCaseQty" 
| eval foo=Dimension+Mixed+OrientationError+ProtrusionError+OffCentreError 
| table _time reporttype OrderId CaseTypeId Location PalletLayers TrayQty CaseQty TrayError foo Dimension Mixed OrientationError LengthError WidthError HeightError ProtrusionError OffCentreError 
| where isnotnull(CaseQty)
| collect index=analyst&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 17:40:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669905#M229702</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2023-11-27T17:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669912#M229705</link>
      <description>&lt;P&gt;Assuming _time and OrderId uniquely identify events in the search and summary index, try something like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=ABC (sourcetype=DepTsuEventTrackingUpdate DepTsuEventTrackingUpdate.LocationQualifiedName=Tray* DepTsuEventTrackingUpdate.TsuSuspect.TsuSuspectReason!=null AND DepTsuEventTrackingUpdate.TsuSuspect.TsuSuspectReason!="TsuUnknownContent") OR (sourcetype=DepTsuEventContentMove) 
| foreach *.OrderId 
    [| eval OrderId=coalesce('OrderId','&amp;lt;&amp;lt;FIELD&amp;gt;&amp;gt;')] 
| replace ProtrusionFront with Protrusion , ProtrusionBack with Protrusion , ProtrusionLeft with Protrusion , ProtrusionRight with Protrusion , ProtrusionTop with Protrusion 
| rename DepTsuEventTrackingUpdate.TsuSuspect.CheckResult.CheckType as Error DepTsuEventTrackingUpdate.TsuSuspect.TsuSuspectReason as TsuSuspectReason DepTsuEventContentMove.SenderFmInstanceName as Location DepTsuEventTrackingUpdate.TsuId as TsuId DepTsuEventContentMove.TsuContent.Quantity as Quantity DepTsuEventContentMove.LocationQualifiedName as TrayLoad DepTsuEventContentMove.TsuContent.CaseTypeId as CaseTypeId
| eval OrientationError=if(Error="Orientation","1","0") , ProtrusionError=if(Error="Protrusion","1","0") , LengthError=if(Error="Length","1","0") , WidthError=if(Error="Width","1","0") , HeightError=if(Error="Height","1","0") , OffCentreError=if(Error="OffCentre","1","0") 
| eval DimensionError=if(LengthError&amp;gt;0 OR WidthError&amp;gt;0 OR HeightError&amp;gt;0, "1","0") 
| eval ErrorQty=(OrientationError+ProtrusionError+DimensionError+OffCentreError) , TrayError=(OrientationError+ProtrusionError+LengthError+WidthError+HeightError+OffCentreError) , TrayError=if(TrayError&amp;gt;0,"1",null) 
| eval Dimension=if(DimensionError&amp;gt;0 AND ErrorQty="1" ,"1","0") , Orientation=if(OrientationError="1" AND ErrorQty="1","1","0") , Protrusion=if(ProtrusionError="1" AND ErrorQty="1","1","0") , Length=if(LengthError="1" AND ErrorQty="1","1","0") , Width=if(WidthError="1" AND ErrorQty="1","1","0") , Height=if(HeightError="1" AND ErrorQty="1","1","0") , OffCentre=if(OffCentreError="1" AND ErrorQty="1","1","0") , Mixed=if(Dimension="0" AND ErrorQty&amp;gt;1,"1","0") 
| eval Layer=if(TrayLoad="PalletInPosition","1",null) , CaseQty=if(TrayLoad="TrayLoad1" OR TrayLoad="TrayLoad2",Quantity,null) , Tray=if(TrayLoad="TrayLoad1" OR TrayLoad="TrayLoad2","1",null) 
| stats min(_time) as _time values(Location) as Location sum(Layer) as PalletLayers sum(Tray) as TrayQty sum(CaseQty) as CaseQty sum(TrayError) as TrayError sum(Orientation) as OrientationError sum(Length) as LengthError sum(Width) as WidthError sum(Height) as HeightError sum(Protrusion) as ProtrusionError sum(OffCentre) as OffCentreError sum(Dimension) as Dimension sum(Mixed) as Mixed values(CaseTypeId) as CaseTypeId by OrderId 
| eval reporttype="DepTrayCaseQty" 
| eval foo=Dimension+Mixed+OrientationError+ProtrusionError+OffCentreError 
| table _time reporttype OrderId CaseTypeId Location PalletLayers TrayQty CaseQty TrayError foo Dimension Mixed OrientationError LengthError WidthError HeightError ProtrusionError OffCentreError 
| where isnotnull(CaseQty)
| eval flag=1
| append [search index=analyst
  | eval flag=2]
| eventstats sum(flag) as flags by _time OrderId
| where flags = 1
| fields - flag flags
| collect index=analyst&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 27 Nov 2023 18:19:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669912#M229705</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-27T18:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669915#M229706</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/225168"&gt;@ITWhisperer&lt;/a&gt;&amp;nbsp;I will try this by tommorow when I am on my machine as a workaround.&lt;/P&gt;&lt;P&gt;I am still not figuring out from where two extra stash file created. Please help me to identify those things. What do I need to check? I have checked audit index logs and internal index logs but nothing I have found.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="uagraw01_0-1701189410228.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28278i82F1C5A912572EB1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="uagraw01_0-1701189410228.png" alt="uagraw01_0-1701189410228.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 16:38:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/669915#M229706</guid>
      <dc:creator>uagraw01</dc:creator>
      <dc:date>2023-11-28T16:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: splunk summary index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/670134#M229775</link>
      <description>&lt;P&gt;As I said before, these searches appear to have been executed on 22nd, you should check your audit around these times (for my time zones, this appears to be just before 02:10am and 04:04am)&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 10:44:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/splunk-summary-index/m-p/670134#M229775</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-11-29T10:44:48Z</dc:date>
    </item>
  </channel>
</rss>

