Knowledge Management

Summary indexing: Results are being returned, but why are extra fields (report) not filtering events as expected in Splunk 6.2?

guilmxm
SplunkTrust
SplunkTrust

Hi !

Running Splunk 6.2, i have a problem with Summary indexing and extra fields not working as expected.

I have a scheduled search which generates summary data in a dedicated index using an extra fields: report=my_report

When i search over the index and the summary report, like:

index=my_index report=my_report

Results are ok BUT Splunk scans for all events of the index during the time range, like if the report fields would not be an indexed field but an extracted field.

For example, my report returns a few hundreds events but Splunk searches for millions of events before returning the result...

If i filter over the "source" field instead of the report extra fields, then the search only takes a few seconds, returning same number of events but scanning only required events !

index=my_index source=name_of_the_schedules_search

Is there anything i am missing ? I don't remember i had this problem with previous release

Thank you very much for your help!

Guilhem

0 Karma
1 Solution

guilmxm
SplunkTrust
SplunkTrust

Could not clearly reproduce the problem, that seems to temporarily happens upon Splunk restart, until Splunk terminates metadata rebuild...

View solution in original post

0 Karma

guilmxm
SplunkTrust
SplunkTrust

Could not clearly reproduce the problem, that seems to temporarily happens upon Splunk restart, until Splunk terminates metadata rebuild...

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...