Splunk Search

Why is summary index is missing a few indexes in its output?

Path Finder

Hi,

I am using around 8 indexes to create a summary index. But after creating the summary index, i am seeing the data for only 6 indexes and 2 indexes were missing.

Please help me with reason and steps to rectify. I need to see all the 8 indexes in the output.

0 Karma

SplunkTrust
SplunkTrust

What is you summary index search?

0 Karma

Legend

Hi umsundar2015,
did you write twice this question (see 496099)?
every way, run the search you are using to populate summary index without summarization command and with a filter on the two loss indexes and see is there are events that match your condition, probably you're using a wrong condition.
Bye.
Giuseppe

0 Karma

Path Finder

thanks Giuseppe

But i have all the index values when i run it without summarization. i mean in normal search format.
But after summarization the index values are missing like index=dem(newly created summary index)

what might be the reason ...

0 Karma