In our 5.0.2 Splunk version installation we have many simultaneous summary index-populating searches.
Sometimes summary indexes are populated in wrong way. For example, summary index A have not only data from saved search populating this index, but also data from another saved search, configurated to populate index B for example.
This issue is randomic and not on same indexes.
We have already and many times checked events producted from single saved searches and we have not found problems; also in logs there are no errors.
Thanks
I am experiencing the same issue, version 5.0.1. The search_name field and other additional fields that get created by the summary are all populated correctly, but the data source and index are incorrect.