Splunk Enterprise

Strange behaviour of collect command

nembela
Path Finder

Hi,

 

I use collect for to create a summary about VPN login and logout events. This worked fine but on last week I have 24 hours of logout events missing. Meanwhile the summary of login events were created.

I checked the search without the collect command and it gives the correct output. I tried it with a test index and it worked too.

But when I run the search for the missing timeframe nothing appears in the destination index.

Do you have any advice what else could I check?

 

Thanks

Labels (1)
0 Karma

nembela
Path Finder

Thanks for the answer. The saved search is working just fine since this accident.

For testing reason I created a new index and rerun the search with the relevant timeframe. It was working fine with the test index.

However when I rerun the search to send the missing events to the real destination index, nothing happens. The search gives results but these results don't show up in the destination index.

I found this log event:

06-21-2024 09:55:08.916 +0200 INFO SavedSearchHistory - pruning saved search history for savedsearch_id=<my_user_name>;vpn;SUM - VPN - Logout events reason=user=<my_user_name> does not exist

It looks like as if something happened to my user during this period.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Did the scheduled search run successfully?

Can you rerun the search with the relevant timeframe and simple add the missing events to the summary index?

Note, I did a BSides talk on Summary indexing Idempotency which you might find useful - it is available on YouTube here

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  &#x1f680; Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...