Monitoring Splunk

summary index not showing any events

prasireddy
Explorer

hi team,
I wanted to create summary index using the following query.

Daily Request counts Last Month

 

index=service_audit REQUEST
| bucket span=d _time
| eval time_diff=round(((stopDate - startDate)/3600000),0)
| stats count as Request_Count by _time

 

 
1.I followed all the steps mentioned in the splunk.com 
2.i have created new summary index as name service_audit_summary 

prasireddy_2-1724775622090.png

3.using collect command 

 

index=service_audit REQUEST
| bucket span=d _time
| eval time_diff=round(((stopDate - startDate)/3600000),0)
| stats count as Request_Count by _time
| collect index=service_audit_summary 

 

but the summary index not showing any event ?

prasireddy_0-1724775453498.png

 

prasireddy_1-1724775512077.png

 

4.even created report and tried but same problem I'm facing 
please anyone could suggest 


Thanks in advance 

Labels (2)
0 Karma

PaulPanther
Motivator

@prasireddy Sorry was on vacation the last two weeks. Are you still facing the issue?

0 Karma

PaulPanther
Motivator

Please execute your original search without testmode=true and after the execution please click on Job --> Inspect Job.

Check if you see any error message in the popup.

 

PaulPanther_0-1724926253677.png

 

0 Karma

prasireddy
Explorer

hi @PaulPanther 

This is the screen shot of Job --> Inspect Job. Please I need help on this asap.

prasireddy_0-1725370746251.png

 

0 Karma

PaulPanther
Motivator

Please set testmode=true in your collect command and please post the outcome. 

0 Karma

prasireddy
Explorer

 

Hi @PaulPanther this is screen shot after adding testmode=true

prasireddy_0-1724849048921.png

 

0 Karma

PaulPanther
Motivator

Okay, looks good. Could you please search in the summary index over all time? And please ensure you have access to the summary index.

0 Karma

prasireddy
Explorer



Hi @PaulPanther Still same I'm Facing Issue

prasireddy_0-1724855283286.png

How can check weather I have access to the summary index. could you please help me.

0 Karma

prasireddy
Explorer

Hi @PaulPanther
I believe I have access

 

prasireddy_0-1724855949193.png

 

0 Karma
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...