Reporting

Summary reports not updating

a212830
Champion

Hi,

I have some dashboard which use summary reports. We had some problems recently, and a number of the reports came back with zero events, and that is appearing in the dashboard. The job is scheduled to run everynight at midnight. My assumption was that the data would fill-in the next day, but that's not happening. How can I get this summary report data to update?

0 Karma

somesoni2
Revered Legend

Check the scheduler logs (index=_internal sourcetype=scheduler savedsearch_name=YourSummaryIndexSearchNameHere) to see if they are running OR not. If for some reason they didn't run (but running now), you would've to backfill it for those missing days. See these
https://docs.splunk.com/Documentation/Splunk/7.0.0/Knowledge/Managesummaryindexgapsandoverlaps
https://wiki.splunk.com/Community:Summary_Indexing_Back_Fill

0 Karma

somesoni2
Revered Legend

Check the scheduler logs (index=_internal sourcetype=scheduler savedsearch_name=YourSummaryIndexSearchNameHere) to see if they are running OR not. If for some reason they didn't run (but running now), you would've to backfill it for those missing days. See these
https://docs.splunk.com/Documentation/Splunk/7.0.0/Knowledge/Managesummaryindexgapsandoverlaps
https://wiki.splunk.com/Community:Summary_Indexing_Back_Fill

sloshburch
Splunk Employee
Splunk Employee

Bingo. Summary Indexing has no dedicated UI. It's just captured results of a scheduled search so unfortunately you'll have to do some debugging into the search that generates the data to understand what's up.

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...