Getting Data In

Data Loss Issue with Index and Summary Index, is it the Transaction command?

New Member


I have a weird problem with some data that is gone after some days but not in a summary index based on the first. I'll explain myself.

I have an index in which I use this data to get some results. With my query in a 24h range of time. I created a summary index with almost the same query (saved search) to show similar info on another dashboard (Historic).

If you launch both queries (the original and the saved search for the summary index) you get the same number of events but, when I run a search with the summary index, some dates, I find that results with the query launched against the summary index does not fit with the other index. Let's say I get 50 events with the original index and 60 from the summary index. How can that be??

I've been told TRANSACTION command can generate some troubles in using it sometimes. Is this true? I use this command in the original index and in the saved search to feed the summary index, not the one is run to show info based on the summary index.




Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...