<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you handle Summary Indexing in a distributed environment? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57887#M11323</link>
    <description>&lt;P&gt;If you don't create the "dummy" index on the search head you will get this error: &lt;/P&gt;

&lt;P&gt;Encountered the following error while trying to update: In handler 'savedsearch': Index name=your_index_here does not exist. The summary index must exist in order for a scheduled search to populate it.&lt;/P&gt;

&lt;P&gt;The search head uses indexes.conf to build a list of indexes it can operate on.  So without it listed on the search head, you'll get this error.&lt;/P&gt;

&lt;P&gt;Putting it on the SH also fixes autocomplete so when you type index=  in the search bar that index shows up.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 14:10:50 GMT</pubDate>
    <dc:creator>khourihan_splun</dc:creator>
    <dc:date>2020-09-28T14:10:50Z</dc:date>
    <item>
      <title>How do you handle Summary Indexing in a distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57882#M11318</link>
      <description>&lt;P&gt;I'm very curious to hear how other admins are handling summary indexing with multiple indexers and search heads.&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Schedule them on 1 Search Head?&lt;/LI&gt;
&lt;LI&gt;Schedule on multiple SHs with Pooling enabled?&lt;/LI&gt;
&lt;LI&gt;Schedule them on each Indexer?&lt;/LI&gt;
&lt;LI&gt;Schedule them on 1 Indexer with distributed search to the others?&lt;/LI&gt;
&lt;LI&gt;Have a dedicated "Collection" Search Head?&lt;/LI&gt;
&lt;LI&gt;Send the results to the Indexers?&lt;/LI&gt;
&lt;LI&gt;Set up local Summary Indexes on the SH(s)?&lt;/LI&gt;
&lt;LI&gt;Dedicated Summary Indexers?&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;It seems like every option above is imperfect, making for many compromises. Please share your SI architecture and why you chose it.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;
jon&lt;/P&gt;

&lt;P&gt;EDIT - I found &lt;A href="http://splunk-base.splunk.com/answers/5837/summary-indexing-on-a-search-head"&gt;this previous answer&lt;/A&gt;. It still leaves some questions though. If I want to search from the SH and collect into an index on the indexer, do I need to create a "dummy" index on the search head? Without the custom index on the SH, it won't let me schedule it. Seems a little hacky.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2012 18:44:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57882#M11318</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2012-01-25T18:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: How do you handle Summary Indexing in a distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57883#M11319</link>
      <description>&lt;P&gt;I have 1 search head and 2 indexers (all are individual physical machines).  I don't have any real indexes on my search head - everything gets forwarded to the 2 indexers.  This includes Summary Indexes.  So I create a summary index on my search head and both indexers, just to ensure everything works okay.&lt;/P&gt;

&lt;P&gt;It does seem a little hacky, but it's probably the best way to handle it.&lt;/P&gt;

&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2012 20:41:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57883#M11319</guid>
      <dc:creator>Brian_Osburn</dc:creator>
      <dc:date>2012-01-25T20:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do you handle Summary Indexing in a distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57884#M11320</link>
      <description>&lt;P&gt;I have the same issue, and I was looking for you to solve my problem for me.  I tried to set up a search and store the sumary index on one of the search heads.  I set up an index on the one SH and I use a pool for my SHs.  The problem is the other SH wants to run it and seems to be doing so, it is just not saving the data.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2012 17:29:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57884#M11320</guid>
      <dc:creator>fk319</dc:creator>
      <dc:date>2012-01-30T17:29:27Z</dc:date>
    </item>
    <item>
      <title>Re: How do you handle Summary Indexing in a distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57885#M11321</link>
      <description>&lt;P&gt;Brian, how do you tell your search where your search index actually resides? (ie how do you forward your search results back to the indexers?)&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2012 18:20:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57885#M11321</guid>
      <dc:creator>fk319</dc:creator>
      <dc:date>2012-01-30T18:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do you handle Summary Indexing in a distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57886#M11322</link>
      <description>&lt;P&gt;You set up the search head with search peers - Splunk handles the rest in the background.&lt;/P&gt;

&lt;P&gt;Take a look at: &lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3/Deploy/Configuredistributedsearch"&gt;http://docs.splunk.com/Documentation/Splunk/4.3/Deploy/Configuredistributedsearch&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2012 19:14:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57886#M11322</guid>
      <dc:creator>Brian_Osburn</dc:creator>
      <dc:date>2012-01-30T19:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: How do you handle Summary Indexing in a distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57887#M11323</link>
      <description>&lt;P&gt;If you don't create the "dummy" index on the search head you will get this error: &lt;/P&gt;

&lt;P&gt;Encountered the following error while trying to update: In handler 'savedsearch': Index name=your_index_here does not exist. The summary index must exist in order for a scheduled search to populate it.&lt;/P&gt;

&lt;P&gt;The search head uses indexes.conf to build a list of indexes it can operate on.  So without it listed on the search head, you'll get this error.&lt;/P&gt;

&lt;P&gt;Putting it on the SH also fixes autocomplete so when you type index=  in the search bar that index shows up.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:10:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57887#M11323</guid>
      <dc:creator>khourihan_splun</dc:creator>
      <dc:date>2020-09-28T14:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: How do you handle Summary Indexing in a distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57888#M11324</link>
      <description>&lt;P&gt;Forwarding the events and summaries to your indexers and turning off indexing on the Search Head is a best practice for several reasons:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;It makes sure the data is replicated and backed up via the index cluster.  (resilient)&lt;/LI&gt;
&lt;LI&gt;If you add another search head the users on that search head will see the same data. (consistent)&lt;/LI&gt;
&lt;LI&gt;It distributes the search load among several indexers reducing the time for a large search to complete. (performant)&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;Hope this helps,&lt;BR /&gt;
Kyle&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2013 20:37:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57888#M11324</guid>
      <dc:creator>khourihan_splun</dc:creator>
      <dc:date>2013-06-26T20:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: How do you handle Summary Indexing in a distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57889#M11325</link>
      <description>&lt;P&gt;Distributed searching is completely different from distributed indexing.  fk319 asked about the latter and Brian Osburn replied about the former.    Distributed indexing is about multiple indexers simultaneously indexing information.  Distributed searching is about searching multiple indexer nodes (any spunk instance with indexed data) simultaneously pulling indexed information back and merging the results.  Search peers are indexer nodes specified for searching.&lt;/P&gt;

&lt;P&gt;Setting up search peers merely enables you to search indexer nodes.  All indexed data stored by "collect" is stored locally.&lt;/P&gt;

&lt;P&gt;The option of using search pooling to share KO bundles can really kill performance because it copies all the KO, including the summary indexing for local copies on each search head.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Feb 2015 17:34:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-you-handle-Summary-Indexing-in-a-distributed-environment/m-p/57889#M11325</guid>
      <dc:creator>landen99</dc:creator>
      <dc:date>2015-02-25T17:34:02Z</dc:date>
    </item>
  </channel>
</rss>

