Reporting

Durable Search does not refill the data

blablabla
Path Finder

Hello, 

I have a scheduled report, which is used to fill a summary index. 

  • The report for the summary index is scheduled hourly (based on indextime)
  • The event data is usually indexed on daily basis at once (sometimes though there are multiple data ingestions of the server per day)

Now the thing is, that the search is inefficient. In normal cases, this is no issue, but when a day was skipped for ingestion and the next day therefore indexes two days of event data at once, the report for the summary index will crash and there will be a gap in the summary index.

To avoid data gaps, I configured the search to be durable

This is the configuration regarding the time constraints of the search:

blablabla_0-1648106475925.png

This is the configuration for the durable search (Backfill method is multiple, as it is recommended for searches with transforming commands)

blablabla_2-1648106629673.png

To test, if data gaps of the summary index are recovered automatically, I stopped the dataflow of for the event index for 5 days and then indexed all the data at once, knowing, that this will lead the scheduled report to crash.

Unfortunately, the durable search did not recover the data gap of the summary index. From the 5 days only a few hours were indexed into the summary index. Does someone have an idea why this is so?

Thanks and best regards

 

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...