<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to setup summary index without si* command? in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/How-to-setup-summary-index-without-si-command/m-p/473396#M4201</link>
    <description>&lt;P&gt;I have tried using the &lt;CODE&gt;collect&lt;/CODE&gt; and also the &lt;CODE&gt;Summary Index&lt;/CODE&gt; thru Splunk Web.&lt;BR /&gt;
What do you mean by forward its logs to the indexers?&lt;/P&gt;</description>
    <pubDate>Tue, 31 Dec 2019 09:07:00 GMT</pubDate>
    <dc:creator>natvaldev</dc:creator>
    <dc:date>2019-12-31T09:07:00Z</dc:date>
    <item>
      <title>How to setup summary index without si* command?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-setup-summary-index-without-si-command/m-p/473392#M4197</link>
      <description>&lt;P&gt;I have followed this &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.1/Knowledge/Usesummaryindexing" target="_blank"&gt;guide&lt;/A&gt;.&lt;BR /&gt;My search is a simple one, just to export errors to another index:&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;index=index_1 ... level&amp;gt;30
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;After the scheduled job finished running, the index is empty.&lt;BR /&gt;I am a bit confued when to use the &lt;CODE&gt;collect&lt;/CODE&gt; command.&lt;/P&gt;
&lt;P&gt;I have configured the search (report) with the summary index, but nothing happened...&lt;/P&gt;
&lt;P&gt;What am I doing wrong?&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jun 2020 17:39:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-setup-summary-index-without-si-command/m-p/473392#M4197</guid>
      <dc:creator>natvaldev</dc:creator>
      <dc:date>2020-06-06T17:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup summary index without si* command?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-setup-summary-index-without-si-command/m-p/473393#M4198</link>
      <description>&lt;P&gt;Did you "Set up summary index searches in Splunk Web?", as documented on &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Usesummaryindexing"&gt;Use summary indexing for increased reporting efficiency&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;Or you can use the collect command in the search, I use the above via Splunk Web as per the docs...&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2019 22:47:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-setup-summary-index-without-si-command/m-p/473393#M4198</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2019-12-30T22:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup summary index without si* command?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-setup-summary-index-without-si-command/m-p/473394#M4199</link>
      <description>&lt;P&gt;Yes I have set it up as documented in the link you posted. scheduling and setting up the summary index, but still no values when I run the search on the summary index&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2019 07:46:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-setup-summary-index-without-si-command/m-p/473394#M4199</guid>
      <dc:creator>natvaldev</dc:creator>
      <dc:date>2019-12-31T07:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup summary index without si* command?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-setup-summary-index-without-si-command/m-p/473395#M4200</link>
      <description>&lt;P&gt;Does the search head forward it's logs to the indexers?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2019 08:16:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-setup-summary-index-without-si-command/m-p/473395#M4200</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2019-12-31T08:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup summary index without si* command?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-setup-summary-index-without-si-command/m-p/473396#M4201</link>
      <description>&lt;P&gt;I have tried using the &lt;CODE&gt;collect&lt;/CODE&gt; and also the &lt;CODE&gt;Summary Index&lt;/CODE&gt; thru Splunk Web.&lt;BR /&gt;
What do you mean by forward its logs to the indexers?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2019 09:07:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-setup-summary-index-without-si-command/m-p/473396#M4201</guid>
      <dc:creator>natvaldev</dc:creator>
      <dc:date>2019-12-31T09:07:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to setup summary index without si* command?</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/How-to-setup-summary-index-without-si-command/m-p/473397#M4202</link>
      <description>&lt;P&gt;Are your indexers different servers to your search heads?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Dec 2019 09:57:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/How-to-setup-summary-index-without-si-command/m-p/473397#M4202</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2019-12-31T09:57:42Z</dc:date>
    </item>
  </channel>
</rss>

