- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
saved searches populates wrong summary index
my_splunk
Path Finder
09-18-2013
08:23 AM
In our 5.0.2 Splunk version installation we have many simultaneous summary index-populating searches.
Sometimes summary indexes are populated in wrong way. For example, summary index A have not only data from saved search populating this index, but also data from another saved search, configurated to populate index B for example.
This issue is randomic and not on same indexes.
We have already and many times checked events producted from single saved searches and we have not found problems; also in logs there are no errors.
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
magnuschill
New Member
09-30-2013
09:02 AM
I am experiencing the same issue, version 5.0.1. The search_name field and other additional fields that get created by the summary are all populated correctly, but the data source and index are incorrect.
