<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Summary index syslog events doing line merge in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Summary-index-syslog-events-doing-line-merge/m-p/109013#M22955</link>
    <description>&lt;P&gt;vcarbona,&lt;/P&gt;

&lt;P&gt;You are correct in that summary indexes typically contain aggregated data and not actual events.  &lt;/P&gt;

&lt;P&gt;If you desire a smaller subset of actual events consider creating an index to route specific events based on some criteria. &lt;/P&gt;

&lt;P&gt;I would not recommend changing any of the default behavior for the stash sourcetype as this is likely to have adverse affects.&lt;/P&gt;</description>
    <pubDate>Thu, 26 May 2011 23:36:46 GMT</pubDate>
    <dc:creator>hazekamp</dc:creator>
    <dc:date>2011-05-26T23:36:46Z</dc:date>
    <item>
      <title>Summary index syslog events doing line merge</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Summary-index-syslog-events-doing-line-merge/m-p/109012#M22954</link>
      <description>&lt;P&gt;A colleague of mine is summary indexing syslog events from a bigger syslog index. He's doing this to have a more focused and quicker search of the data. However, the syslog events in the summary index are merging from time to time which makes reporting by field impossible. I know with regular indexes there is a SHOULD_LINEMERGE configuration setting, but is there a way to configure the summary index that way? I'm afraid to break something if I add a "SHOULD_LINEMERGE = False" to the "stash" sourcetype. &lt;/P&gt;

&lt;P&gt;Additional question: Is it appropriate to put entire events into a summary index? I always thought that summary indexing was used to store aggregated data and not actual entire events.&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2011 20:24:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Summary-index-syslog-events-doing-line-merge/m-p/109012#M22954</guid>
      <dc:creator>vcarbona</dc:creator>
      <dc:date>2011-05-26T20:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Summary index syslog events doing line merge</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Summary-index-syslog-events-doing-line-merge/m-p/109013#M22955</link>
      <description>&lt;P&gt;vcarbona,&lt;/P&gt;

&lt;P&gt;You are correct in that summary indexes typically contain aggregated data and not actual events.  &lt;/P&gt;

&lt;P&gt;If you desire a smaller subset of actual events consider creating an index to route specific events based on some criteria. &lt;/P&gt;

&lt;P&gt;I would not recommend changing any of the default behavior for the stash sourcetype as this is likely to have adverse affects.&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2011 23:36:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Summary-index-syslog-events-doing-line-merge/m-p/109013#M22955</guid>
      <dc:creator>hazekamp</dc:creator>
      <dc:date>2011-05-26T23:36:46Z</dc:date>
    </item>
  </channel>
</rss>

