Reporting

Durable Search does not refill the data

blablabla
Path Finder

Hello, 

I have a scheduled report, which is used to fill a summary index. 

  • The report for the summary index is scheduled hourly (based on indextime)
  • The event data is usually indexed on daily basis at once (sometimes though there are multiple data ingestions of the server per day)

Now the thing is, that the search is inefficient. In normal cases, this is no issue, but when a day was skipped for ingestion and the next day therefore indexes two days of event data at once, the report for the summary index will crash and there will be a gap in the summary index.

To avoid data gaps, I configured the search to be durable

This is the configuration regarding the time constraints of the search:

blablabla_0-1648106475925.png

This is the configuration for the durable search (Backfill method is multiple, as it is recommended for searches with transforming commands)

blablabla_2-1648106629673.png

To test, if data gaps of the summary index are recovered automatically, I stopped the dataflow of for the event index for 5 days and then indexed all the data at once, knowing, that this will lead the scheduled report to crash.

Unfortunately, the durable search did not recover the data gap of the summary index. From the 5 days only a few hours were indexed into the summary index. Does someone have an idea why this is so?

Thanks and best regards

 

Labels (3)
0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...