Knowledge Management

stash_new file is not written to summary index

aluetjen
Explorer

I created a summary index summary_example.

Using the 'collect' command I wrote events into a stash_new file.

SomeSearch | sitimechart span=1h max(SomeMetric) by Name | collect index=summary_example

I receive a message that the file has been successfully written:

Changing file extension to .stash_new for file=$random$_events.stash

Successfully wrote file to '106082206_events.stash_new'.

However, the search result does not appear in the index.

I searched index=_internal "106082206_events.stash_new" but didn't receive any events (other than the events to the search on the internal index itself).

How can I trouble shoot?

Tags (2)
0 Karma

aluetjen
Explorer

Restart of splunk solved the issue.

I searched the internal internal index for the summary index name and noticed that splunk wasn't happy to load the new index.

pacrip
Path Finder

Hi all, Im seeing similar behaviour to this in my 6.3 instance, is it meant to act like this? Its not ideal to have to repair the bucket every time you add new summary indexed events...

0 Karma

ahofmann
Explorer

Did you ever find out any more info on this? I'm having the same issue, solved by a restart.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...