Knowledge Management

Issue with Summary Indexing, saved searches runs fine but summary index data is not written sometimes

somesoni2
Revered Legend

I have a set of 10 saved searches which are doing summary indexing. These searches are running every minute. All the searches run fine and returns data when runs manually. They also return data when running through Saved Searches [as per _internal log (index=_internal sourcetype=scheduler )], but sometimes the data is not written into summary index for some of the searches.
This happens very randomly. I have verified the _internal logs and there is result_count > 0 for searches. There is no error or warning reported.
What could be the reason for the same and what all troubleshooting steps I can try out for it?

1 Solution

yannK
Splunk Employee
Splunk Employee

Look in the spooler for files that were skipped.
$SPLUNK_HOME/var/spool/splunk

If you find many old files, this is a know bug for version prior to 5.0.3
see http://answers.splunk.com/answers/70072/summary-indexing-blocked-and-binary-file-warning

View solution in original post

yannK
Splunk Employee
Splunk Employee

Look in the spooler for files that were skipped.
$SPLUNK_HOME/var/spool/splunk

If you find many old files, this is a know bug for version prior to 5.0.3
see http://answers.splunk.com/answers/70072/summary-indexing-blocked-and-binary-file-warning

my_splunk
Path Finder

Hi somesoni2, i have a problem as your with my saved searches. Have you found a solution?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...