<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk summary indexing for critical data in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-summary-indexing-for-critical-data/m-p/141947#M1412</link>
    <description>&lt;P&gt;Hi together,&lt;/P&gt;

&lt;P&gt;I'am using summary indexing to aggregate big amounts of critical data in 5 minute frames.&lt;/P&gt;

&lt;P&gt;Now I'am asking myself is summary-indexing for critical (business) data a good solution by scheduled timeframes?&lt;/P&gt;

&lt;P&gt;What is splunk doing if there is e.g. a maintenanance window about 1 hour? Is there a gap in the data? What is the best practise how to handle these cases to avoid gaps?&lt;/P&gt;

&lt;P&gt;Best regards&lt;BR /&gt;
Steffen&lt;/P&gt;</description>
    <pubDate>Thu, 14 Nov 2013 09:49:35 GMT</pubDate>
    <dc:creator>tcoq</dc:creator>
    <dc:date>2013-11-14T09:49:35Z</dc:date>
    <item>
      <title>Splunk summary indexing for critical data</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-summary-indexing-for-critical-data/m-p/141947#M1412</link>
      <description>&lt;P&gt;Hi together,&lt;/P&gt;

&lt;P&gt;I'am using summary indexing to aggregate big amounts of critical data in 5 minute frames.&lt;/P&gt;

&lt;P&gt;Now I'am asking myself is summary-indexing for critical (business) data a good solution by scheduled timeframes?&lt;/P&gt;

&lt;P&gt;What is splunk doing if there is e.g. a maintenanance window about 1 hour? Is there a gap in the data? What is the best practise how to handle these cases to avoid gaps?&lt;/P&gt;

&lt;P&gt;Best regards&lt;BR /&gt;
Steffen&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2013 09:49:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-summary-indexing-for-critical-data/m-p/141947#M1412</guid>
      <dc:creator>tcoq</dc:creator>
      <dc:date>2013-11-14T09:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk summary indexing for critical data</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-summary-indexing-for-critical-data/m-p/141948#M1413</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;Yes, if the scheduled search to summarize the data is not executed, you will get gaps. Those gaps can be filled running the backfill command:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Managesummaryindexgapsandoverlaps"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Managesummaryindexgapsandoverlaps&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Did you tried report acceleration? It does something simmilar but without need of managing the gaps.&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2013 10:03:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-summary-indexing-for-critical-data/m-p/141948#M1413</guid>
      <dc:creator>gfuente</dc:creator>
      <dc:date>2013-11-14T10:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk summary indexing for critical data</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-summary-indexing-for-critical-data/m-p/141949#M1414</link>
      <description>&lt;P&gt;Great, thank you for this link. &lt;/P&gt;

&lt;P&gt;But I see chapter: "Searches that run longer than their scheduled intervals:" &lt;/P&gt;

&lt;P&gt;From my understanding there could by some cases where it's not direct visible for me, if there occurs some gaps? &lt;/P&gt;

&lt;P&gt;So acceleration is the prefered way to handle critical data? I can try this.&lt;/P&gt;

&lt;P&gt;Best regards...&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2013 10:17:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-summary-indexing-for-critical-data/m-p/141949#M1414</guid>
      <dc:creator>tcoq</dc:creator>
      <dc:date>2013-11-14T10:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk summary indexing for critical data</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-summary-indexing-for-critical-data/m-p/141950#M1415</link>
      <description>&lt;P&gt;It depends,&lt;/P&gt;

&lt;P&gt;Report Acceleration has some limitations and maybe don fit your needs. &lt;/P&gt;

&lt;P&gt;Regarding the searches running longer than the scheduled intervals. You could run a search to check this and alert if needed.&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2013 10:48:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-summary-indexing-for-critical-data/m-p/141950#M1415</guid>
      <dc:creator>gfuente</dc:creator>
      <dc:date>2013-11-14T10:48:32Z</dc:date>
    </item>
  </channel>
</rss>

