Splunk Search

Question about the PCI Application

jambajuice
Communicator

What is the "stash" sourcetype used for in the application? We're getting two huge spikes of events from that sourcetype every day at 10 pm and 7 am. They are consuming a significant amount of our license. The messages look like the following:

51  
10/28/10
7:59:00.000 AM  
10/28/2010 07:59:00, search_name="PCI 7.1 - Successful Access by Target - Summary Gen", search_now=1288278900.000, info_min_time=1288277700.000, info_max_time=1288278600.000, info_search_time=1288278935.693, dest_bestmatch=0741BOH, psrsvd_gc=2, psrsvd_v=1
host=semvsplunkprd   Options|  sourcetype=stash   Options|  source=PCI 7.1 - Successful Access by Target - Summary Gen   Options

52  
10/28/10
7:59:00.000 AM  
10/28/2010 07:59:00, search_name="PCI 7.1 - Successful Access by Target - Summary Gen", search_now=1288278900.000, info_min_time=1288277700.000, info_max_time=1288278600.000, info_search_time=1288278935.693, dest_bestmatch=0706BOH, psrsvd_gc=1, psrsvd_v=1
host=semvsplunkprd   Options|  sourcetype=stash   Options|  source=PCI 7.1 - Successful Access by Target - Summary Gen   Options

53  
10/28/10
7:59:00.000 AM  
10/28/2010 07:59:00, search_name="PCI 7.1 - Successful Access by Target - Summary Gen", search_now=1288278900.000, info_min_time=1288277700.000, info_max_time=1288278600.000, info_search_time=1288278935.693, dest_bestmatch=0661BOH, psrsvd_gc=2, psrsvd_v=1
host=semvsplunkprd   Options|  sourcetype=stash   Options|  source=PCI 7.1 - Successful Access by Target - Summary Gen   Options
Tags (1)
0 Karma

araitz
Splunk Employee
Splunk Employee

The "stash" sourcetype is used for summary indexing. The Summary Gen in the search names is a good clue. Are the results with sourcetype="stash" showing up outside of index=summary? If properly configured, summary indexing should not count against your indexing volume.

araitz
Splunk Employee
Splunk Employee

Isn't everyone using the latest/greatest??? 😛

0 Karma

southeringtonp
Motivator

Note that this is only true from 4.0.10 onward. Older versions did count summary indexing against your license.

Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...