Reporting

Summary reports not updating

a212830
Champion

Hi,

I have some dashboard which use summary reports. We had some problems recently, and a number of the reports came back with zero events, and that is appearing in the dashboard. The job is scheduled to run everynight at midnight. My assumption was that the data would fill-in the next day, but that's not happening. How can I get this summary report data to update?

0 Karma

somesoni2
Revered Legend

Check the scheduler logs (index=_internal sourcetype=scheduler savedsearch_name=YourSummaryIndexSearchNameHere) to see if they are running OR not. If for some reason they didn't run (but running now), you would've to backfill it for those missing days. See these
https://docs.splunk.com/Documentation/Splunk/7.0.0/Knowledge/Managesummaryindexgapsandoverlaps
https://wiki.splunk.com/Community:Summary_Indexing_Back_Fill

0 Karma

somesoni2
Revered Legend

Check the scheduler logs (index=_internal sourcetype=scheduler savedsearch_name=YourSummaryIndexSearchNameHere) to see if they are running OR not. If for some reason they didn't run (but running now), you would've to backfill it for those missing days. See these
https://docs.splunk.com/Documentation/Splunk/7.0.0/Knowledge/Managesummaryindexgapsandoverlaps
https://wiki.splunk.com/Community:Summary_Indexing_Back_Fill

sloshburch
Splunk Employee
Splunk Employee

Bingo. Summary Indexing has no dedicated UI. It's just captured results of a scheduled search so unfortunately you'll have to do some debugging into the search that generates the data to understand what's up.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...