Other Usage

Events not showing up using summary data

randy_moore
Path Finder

Hi,  I have a report that pulls daily transaction counts from a summary index.  Running the report for "month to date", I don't get results from every day.  
My search is this: 

 

index=summary search_name=Summarization_Daily_Txn App IN ("XXX")) endpoint="ZZZZ"
| bin _time span=1d
| stats sum(Count) AS Txn_Count  by _time
| addcoltotals

 

 
Gives me this output:

randy_moore_0-1638983522130.png

The Dec 2, 4th and 5th totals are missing.    Yes,  I have verified that there are counts for those days. 

If I run the report so that it spans just Dec 4th and 5th, the counts show up.   Just not if I run it using earliest=@mon latest=@d

Any ideas on what I am doing wrong?

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...