Splunk Search

collect command generates multiple rows in summary index for single event


I am using the collect statement to collect a single event to a summary index. When run as a search, it will generate a single row. When run as part of a hidden search in a dashboard, I get multiple repeated rows in the summary index.

If I show the hidden search in a table in the dashboard, I also get the many rows in the summary, but only one in the shown table in the dashboard.

The search is part of a hierarchy of base searches, so the search for the table itself that has the collect statement is one search and there are 5 base searches backing it up.

If I press the rerun search icon in the table, I get 8 rows in the summary, but I normally get 5 or 7.

Anyone know why this is?


Labels (1)
Tags (1)
0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!