Knowledge Management

Issue with Summary Indexing, saved searches runs fine but summary index data is not written sometimes

somesoni2
Revered Legend

I have a set of 10 saved searches which are doing summary indexing. These searches are running every minute. All the searches run fine and returns data when runs manually. They also return data when running through Saved Searches [as per _internal log (index=_internal sourcetype=scheduler )], but sometimes the data is not written into summary index for some of the searches.
This happens very randomly. I have verified the _internal logs and there is result_count > 0 for searches. There is no error or warning reported.
What could be the reason for the same and what all troubleshooting steps I can try out for it?

1 Solution

yannK
Splunk Employee
Splunk Employee

Look in the spooler for files that were skipped.
$SPLUNK_HOME/var/spool/splunk

If you find many old files, this is a know bug for version prior to 5.0.3
see http://answers.splunk.com/answers/70072/summary-indexing-blocked-and-binary-file-warning

View solution in original post

yannK
Splunk Employee
Splunk Employee

Look in the spooler for files that were skipped.
$SPLUNK_HOME/var/spool/splunk

If you find many old files, this is a know bug for version prior to 5.0.3
see http://answers.splunk.com/answers/70072/summary-indexing-blocked-and-binary-file-warning

my_splunk
Path Finder

Hi somesoni2, i have a problem as your with my saved searches. Have you found a solution?

0 Karma
Get Updates on the Splunk Community!

New Dates, New City: Save the Date for .conf25!

Wake up, babe! New .conf25 dates AND location just dropped!! That's right, this year, .conf25 is taking place ...

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...