Knowledge Management

Summary indexing: Results are being returned, but why are extra fields (report) not filtering events as expected in Splunk 6.2?

guilmxm
Influencer

Hi !

Running Splunk 6.2, i have a problem with Summary indexing and extra fields not working as expected.

I have a scheduled search which generates summary data in a dedicated index using an extra fields: report=my_report

When i search over the index and the summary report, like:

index=my_index report=my_report

Results are ok BUT Splunk scans for all events of the index during the time range, like if the report fields would not be an indexed field but an extracted field.

For example, my report returns a few hundreds events but Splunk searches for millions of events before returning the result...

If i filter over the "source" field instead of the report extra fields, then the search only takes a few seconds, returning same number of events but scanning only required events !

index=my_index source=name_of_the_schedules_search

Is there anything i am missing ? I don't remember i had this problem with previous release

Thank you very much for your help!

Guilhem

0 Karma
1 Solution

guilmxm
Influencer

Could not clearly reproduce the problem, that seems to temporarily happens upon Splunk restart, until Splunk terminates metadata rebuild...

View solution in original post

0 Karma

guilmxm
Influencer

Could not clearly reproduce the problem, that seems to temporarily happens upon Splunk restart, until Splunk terminates metadata rebuild...

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...