Knowledge Management

Issue searching againts Summary Index

dshakespeare_sp
Splunk Employee
Splunk Employee

Customer reports issue searching againts Summary Index.

They add a summary index as following:
index="foo-bar" host="my-server" earliest=-1w@w latest=-0w@w | xmlkv | sitimechart span=10m max(foo.bar)

When they run the search they can see data inside, however when I try to search via the summary index they do not get any results when doing timechart.

They have found that all the ones that do not work contain a "." in the field that I try to summarize.

Fields that do not contain a dot work fine

Example search.

index="summary" search_name="My Summary" | timechart span=10m max(foo.bar)

Tags (1)
0 Karma
1 Solution

dshakespeare_sp
Splunk Employee
Splunk Employee

Splunk have identified an issue whereby Splunk's key cleaning rules are being applied to summary indexes (any field that contains characters that are not in a-z, A-Z, and 0-9 ranges are replaced with an underscore (_).

Defect ticket SPL-58300 has been raised for this issue

A workaround is possible by adding CLEAN_KEYS=0 the [stash_extract]
stanza in $SPLUNK/etc/system/local/transforms.conf

View solution in original post

dshakespeare_sp
Splunk Employee
Splunk Employee

Splunk have identified an issue whereby Splunk's key cleaning rules are being applied to summary indexes (any field that contains characters that are not in a-z, A-Z, and 0-9 ranges are replaced with an underscore (_).

Defect ticket SPL-58300 has been raised for this issue

A workaround is possible by adding CLEAN_KEYS=0 the [stash_extract]
stanza in $SPLUNK/etc/system/local/transforms.conf

Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...