Knowledge Management

Issue searching againts Summary Index

dshakespeare_sp
Splunk Employee
Splunk Employee

Customer reports issue searching againts Summary Index.

They add a summary index as following:
index="foo-bar" host="my-server" earliest=-1w@w latest=-0w@w | xmlkv | sitimechart span=10m max(foo.bar)

When they run the search they can see data inside, however when I try to search via the summary index they do not get any results when doing timechart.

They have found that all the ones that do not work contain a "." in the field that I try to summarize.

Fields that do not contain a dot work fine

Example search.

index="summary" search_name="My Summary" | timechart span=10m max(foo.bar)

Tags (1)
0 Karma
1 Solution

dshakespeare_sp
Splunk Employee
Splunk Employee

Splunk have identified an issue whereby Splunk's key cleaning rules are being applied to summary indexes (any field that contains characters that are not in a-z, A-Z, and 0-9 ranges are replaced with an underscore (_).

Defect ticket SPL-58300 has been raised for this issue

A workaround is possible by adding CLEAN_KEYS=0 the [stash_extract]
stanza in $SPLUNK/etc/system/local/transforms.conf

View solution in original post

dshakespeare_sp
Splunk Employee
Splunk Employee

Splunk have identified an issue whereby Splunk's key cleaning rules are being applied to summary indexes (any field that contains characters that are not in a-z, A-Z, and 0-9 ranges are replaced with an underscore (_).

Defect ticket SPL-58300 has been raised for this issue

A workaround is possible by adding CLEAN_KEYS=0 the [stash_extract]
stanza in $SPLUNK/etc/system/local/transforms.conf

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...