Knowledge Management

Summary indexing: Results are being returned, but why are extra fields (report) not filtering events as expected in Splunk 6.2?

guilmxm
Influencer

Hi !

Running Splunk 6.2, i have a problem with Summary indexing and extra fields not working as expected.

I have a scheduled search which generates summary data in a dedicated index using an extra fields: report=my_report

When i search over the index and the summary report, like:

index=my_index report=my_report

Results are ok BUT Splunk scans for all events of the index during the time range, like if the report fields would not be an indexed field but an extracted field.

For example, my report returns a few hundreds events but Splunk searches for millions of events before returning the result...

If i filter over the "source" field instead of the report extra fields, then the search only takes a few seconds, returning same number of events but scanning only required events !

index=my_index source=name_of_the_schedules_search

Is there anything i am missing ? I don't remember i had this problem with previous release

Thank you very much for your help!

Guilhem

0 Karma
1 Solution

guilmxm
Influencer

Could not clearly reproduce the problem, that seems to temporarily happens upon Splunk restart, until Splunk terminates metadata rebuild...

View solution in original post

0 Karma

guilmxm
Influencer

Could not clearly reproduce the problem, that seems to temporarily happens upon Splunk restart, until Splunk terminates metadata rebuild...

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...