Reporting

Durable Search does not refill the data

blablabla
Path Finder

Hello, 

I have a scheduled report, which is used to fill a summary index. 

  • The report for the summary index is scheduled hourly (based on indextime)
  • The event data is usually indexed on daily basis at once (sometimes though there are multiple data ingestions of the server per day)

Now the thing is, that the search is inefficient. In normal cases, this is no issue, but when a day was skipped for ingestion and the next day therefore indexes two days of event data at once, the report for the summary index will crash and there will be a gap in the summary index.

To avoid data gaps, I configured the search to be durable

This is the configuration regarding the time constraints of the search:

blablabla_0-1648106475925.png

This is the configuration for the durable search (Backfill method is multiple, as it is recommended for searches with transforming commands)

blablabla_2-1648106629673.png

To test, if data gaps of the summary index are recovered automatically, I stopped the dataflow of for the event index for 5 days and then indexed all the data at once, knowing, that this will lead the scheduled report to crash.

Unfortunately, the durable search did not recover the data gap of the summary index. From the 5 days only a few hours were indexed into the summary index. Does someone have an idea why this is so?

Thanks and best regards

 

Labels (3)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...