Blog tagged as Summary Index Issues

Summary Index Issues - Splunk Enterprise Troubleshooting Use Case - 22
Issue: 
Timestamp is not extracted properly for the summary index (JSON data copied using collect command)

index=web_idx ......
| collect index="web_summary_idx"

Root cause: 
Default sourcetype of the copied events is "stash". It may not be able to recognize the timestamps i...
14.06.24 07:23 PM - Comment(s)