Knowledge Management

saved searches populates wrong summary index

my_splunk
Path Finder

In our 5.0.2 Splunk version installation we have many simultaneous summary index-populating searches.

Sometimes summary indexes are populated in wrong way. For example, summary index A have not only data from saved search populating this index, but also data from another saved search, configurated to populate index B for example.
This issue is randomic and not on same indexes.

We have already and many times checked events producted from single saved searches and we have not found problems; also in logs there are no errors.

Thanks

Tags (1)
0 Karma

magnuschill
New Member

I am experiencing the same issue, version 5.0.1. The search_name field and other additional fields that get created by the summary are all populated correctly, but the data source and index are incorrect.

0 Karma
Get Updates on the Splunk Community!

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...