<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Summary Index does not seem correct in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-does-not-seem-correct/m-p/463945#M4107</link>
    <description>&lt;P&gt;I have a summary index  I am looking to put data in. &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;| table Name,host,_time, component, operation, userName, responseTimeSeconds&lt;BR /&gt;
    | fields - _raw&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;This is the basis of what I have. When putting it into the summary index I was hoping to have only the fields specified in my table. Instead I am getting things like the following included:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;08/26/2019 12:29:59 -0400, search_name=savedReport, search_now=1566837000.000, info_min_time=1566836700.000, info_max_time=1566837000.000, info_search_time=1566837197.992,&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Is there any way strip out this information in my index? Will it automatically add it. I used &lt;CODE&gt;collect&lt;/CODE&gt; with &lt;CODE&gt;testmode=true&lt;/CODE&gt; and thought that should indicate what my output looks like. Is there a step I am missing or is that what I should expect to have in my data? For awareness what I am trying to do is gather some data we want that will stay around longer than our current setup by stripping out a lot of items in the logging we do not need.&lt;/P&gt;</description>
    <pubDate>Mon, 26 Aug 2019 16:49:46 GMT</pubDate>
    <dc:creator>aohls</dc:creator>
    <dc:date>2019-08-26T16:49:46Z</dc:date>
    <item>
      <title>Summary Index does not seem correct</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-does-not-seem-correct/m-p/463945#M4107</link>
      <description>&lt;P&gt;I have a summary index  I am looking to put data in. &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;| table Name,host,_time, component, operation, userName, responseTimeSeconds&lt;BR /&gt;
    | fields - _raw&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;This is the basis of what I have. When putting it into the summary index I was hoping to have only the fields specified in my table. Instead I am getting things like the following included:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;08/26/2019 12:29:59 -0400, search_name=savedReport, search_now=1566837000.000, info_min_time=1566836700.000, info_max_time=1566837000.000, info_search_time=1566837197.992,&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Is there any way strip out this information in my index? Will it automatically add it. I used &lt;CODE&gt;collect&lt;/CODE&gt; with &lt;CODE&gt;testmode=true&lt;/CODE&gt; and thought that should indicate what my output looks like. Is there a step I am missing or is that what I should expect to have in my data? For awareness what I am trying to do is gather some data we want that will stay around longer than our current setup by stripping out a lot of items in the logging we do not need.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 16:49:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-does-not-seem-correct/m-p/463945#M4107</guid>
      <dc:creator>aohls</dc:creator>
      <dc:date>2019-08-26T16:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index does not seem correct</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-does-not-seem-correct/m-p/463946#M4108</link>
      <description>&lt;P&gt;That is just the way that it works.  If you have spare license, you can always use the &lt;CODE&gt;Log Event&lt;/CODE&gt; action, but it is not free like &lt;CODE&gt;Summary Index&lt;/CODE&gt; is.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 17:55:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-does-not-seem-correct/m-p/463946#M4108</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-08-26T17:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: Summary Index does not seem correct</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-does-not-seem-correct/m-p/463947#M4109</link>
      <description>&lt;P&gt;@woodcock Thanks for the insight.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 18:04:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Summary-Index-does-not-seem-correct/m-p/463947#M4109</guid>
      <dc:creator>aohls</dc:creator>
      <dc:date>2019-08-26T18:04:21Z</dc:date>
    </item>
  </channel>
</rss>

