Reporting

Durable Search does not refill the data

blablabla
Path Finder

Hello, 

I have a scheduled report, which is used to fill a summary index. 

  • The report for the summary index is scheduled hourly (based on indextime)
  • The event data is usually indexed on daily basis at once (sometimes though there are multiple data ingestions of the server per day)

Now the thing is, that the search is inefficient. In normal cases, this is no issue, but when a day was skipped for ingestion and the next day therefore indexes two days of event data at once, the report for the summary index will crash and there will be a gap in the summary index.

To avoid data gaps, I configured the search to be durable

This is the configuration regarding the time constraints of the search:

blablabla_0-1648106475925.png

This is the configuration for the durable search (Backfill method is multiple, as it is recommended for searches with transforming commands)

blablabla_2-1648106629673.png

To test, if data gaps of the summary index are recovered automatically, I stopped the dataflow of for the event index for 5 days and then indexed all the data at once, knowing, that this will lead the scheduled report to crash.

Unfortunately, the durable search did not recover the data gap of the summary index. From the 5 days only a few hours were indexed into the summary index. Does someone have an idea why this is so?

Thanks and best regards

 

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...