Reporting

Scheduled report only intermittently adding data to index

AliDodd
Loves-to-Learn

We have a scheduled report that passes data using "collect" & targeting an index which was running fine on schedule and the information was appearing in the index. It started only intermittently working and now the scheduled occurrences have stopped placing data into the index. The search is still perfectly functional and has results, I cannot work out why these are not being recorded. No change to the search used or the systems.

Search used:

| ldapsearch search="(&(objectClass=user)(!(objectClass=computer)))" attrs="pwdLastset,sAMAccountName,extensionAttribute8,info" |
fields "_time", "extensionAttribute8", "pwdLastSet", "sAMAccountName","info" | where isnotnull('extensionAttribute8') | collect index="ldap_ad"

 

Tried adding 'spool=true' at the end and doing 'addinfo' prior to the collect, neither makes a difference to the search or the report, no data appears in ldap_ad

Labels (1)
0 Karma

KendallW
Contributor

Hi @AliDodd the first thing to check is whether the scheduled searches are being skipped or failed. You can check this from the job manager or the splunk health dashboard. If so, check the errors in the search.log and scheduler.log files. 

If you still can't find the issue, test the collect command is sending data correctly to the index using a quick makeresults command, e.g. (Assuming there is no problem sending a dummy event to your production index!)

| makeresults | eval test="test" | collect index="ldap_ad"

 

0 Karma

AliDodd
Loves-to-Learn

Cheers, I've checked the job manager and the job completes and writes to the stash, as all data is sent on to the indexers (which is is for all other inputs to this HF) that should be fine.

Unfortunately can't use the makeresults command as it needs to be first command in the search which conflicts with the ldapsearch command as that needs the same.

It's almost like the collect command has stopped working..

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...