Knowledge Management

successful summary search but no data in the summary index

paranoid
Explorer

An hourly scheduled summary search finishes successfully:

12-05-2012 05:17:27.966 +0000 INFO SavedSplunker - savedsearch_id="nobody;XXX;Summary Gen", user="nobody", app="XXX", savedsearch_name="Summary Gen", status=success, digest_mode=1, scheduled_time=1354684620, dispatch_time=1354684644, run_time=3.788, result_count=18244, alert_actions="summary_index", sid="scheduler_nobody_ZW1haWxfbWV0cmljc19hcHA_RMD59f64bf9adfa139f1_at_1354684620_60d34ceed7aa64ec", suppressed=0, thread_id="AlertNotifierWorker-0"

search.log in the dispatch directory has this error
12-05-2012 05:17:27.748 ERROR SummaryIndexProcessor - Error moving file '/var/groupon/splunk/var/run/splunk/1354684647.1.tmp' to '/var/groupon/splunk/var/spool/splunk/RMD59f64bf9adfa139f1_1502598233.stash_new'.

As a result the data doesn't arrive in the summary index. Also interesting that the scheduled search is considered successful

What does this error mean? There is plenty of free disk space.

Tags (1)
0 Karma

dart
Splunk Employee
Splunk Employee

The error means that the results file /var/groupon/splunk/var/run/splunk/1354684647.1.tmp could not be moved into the spool directory /var/groupon/splunk/var/spool/splunk which is where it would be picked up to be indexed, which has a sinkhole (delete after indexing) input set up.

Double check the permissions of the folder /var/groupon/splunk/var/spool/splunk. Is it on the same volume as the rest of Splunk or a different one? Are there any files in /var/groupon/splunk/var/spool/splunk?

0 Karma

paranoid
Explorer

The scheduled search works most of the time, so it's not permissions. /var/groupon/splunk/var/spool/splunk has quite a few files, will a name collision explain this?

And then I guess the next question is, why are there so many files there? Files should only live there for the duration of indexing. Some files are fra mid November and we are early December now.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...