Ah - sometimes the easy answer are the answer, but sometimes they're not! So, from what I can see of fill_summary_index.py, the dedup option isn't actually magic. That means there's no reason you can't just make a few minor modifications (mostly to timeframes) to just backfill the summary index manually. Indeed, there's no magic here anyway. If fill_summary_index.py is not filling in your blank areas in the summary index correctly using the saved search from the "regular" collector for the summary index, then it seems to me that it's likely that the main search simply isn't working right anyway. The reasoning here is that when it runs 'normally', it's running over a time period and dumping its output to that summary index. This is exactly what the backfilling version does, with the only difference being that it sets a different start/end time. Again, no magic, just searches running over time periods. So, a couple of ways forward. 1) You could provide the search and maybe we can spot why it doesn't work right for backfilling. 2) You could craft up a "deduplication search" that you can pass to the backfill function to tell it *how* to identify which periods need backfilling. (I don't know how to do this, but the notes for the backfill function says you can do this, so I believe it. And of course, just because I don't know how to do it right now doesn't mean we can't help figure it out, or someone else might!) 3) Or maybe you can just manually run the search that would do the backfilling, only manually selecting the timeframes so that you don't get duplication. I mean, I'd guess it's just a standard saved search that ends up with `| collect...` at the end. 🙂 Anyway, I do hope this helps, and maybe this bump will get someone else who does this a lot to chime in - we'll see!
... View more