- the indexname contains summary but this index is not a summary index.
- Report runs at morning 7 o'clock for the previous day's data and the _time is overwritten to previous date. This is done so that the count is logged in as previous day's data.
The issue which we are facing here is when we run the same query for that time period after a few days( say a month), we are observing the value inside the index=xyz_summary (i.e. count value) is greater than when we run the original query. Interestingly, the results were both the same, when I ran both queries initially a month before.
Any suggestions why is this happening (is it due to collect command) ? what modification can be done so that we dont get a mismatch here.