Hi,
I did an alert that should run every day at the same time, at the end of the alert I used "collect" ->
| collect index="index_name"
every day the job is running (it takes 1~ min) but I don't see the new events after the job is finished...
how long is it supposed to take until I will see it on the index?
this is the search I do (with filter last 24h) ->
index="index_name"
The events given to the collect command are written to splunk's spool directory to be indexed. Check whether there are any holds up in this process. The internal log for any errors or warnings in this area.
what is that?
where can I see this directory?
Hi @stavakler,
Could you better describe your need?
it seems that
is it correct?
Could you share your full search?
Ciao.
Giuseppe
exactly, It seems that it takes hours until the events show on the summary index...
I can't share the full search, but eventually, I do
| table field1, field2, field3 | collect="Index_name"
and after the job finished I tried to find the new events on the index but the search returned 0
Hi @stavakler,
you can check your alert manually running your search and checking if you have results.
If you usually don't have results, you could enlarge the time period or changing (only for test) your conditions to be sure to have results.
Then you can check if the results are in the summary index (that obviously must exist!).
Ciao.
Giuseppe
I do have results...
Hi @stavakler,
sorry I didn't noted it in my first reading, the syntax of collect command is different
| collect index="Index_name"
as you can see at https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/collect
then you can search
index="Index_name"
and find the events.
Ciao.
Giuseppe
This is not the problem... I wrote exactly as said on their page