<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What should I feed to my summary Index? and how Should I extract fields for status, Amount and ID in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/What-should-I-feed-to-my-summary-Index-and-how-Should-I-extract/m-p/571631#M199198</link>
    <description>&lt;P&gt;&lt;SPAN&gt;INFO | 2021-10-18 05:17 AM | BUSINESS RULE | Payload for ID#: &lt;SPAN class=""&gt;58916&lt;/SPAN&gt; with status Approved is published&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Second Event&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;msg&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;&amp;nbsp;INFO | 2021-10-14 10:38 PM |&amp;nbsp; Message consumed: {"InputAmountToCredit":"22.67","CurrencyCode":"AUD","Buid":"1401","OrderNumber":"877118406","Cre ID":"58916"}&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;I want to have sum of InputAmountToCredit based on status . status can vary to different statuses and ID is common field for both the events (but it differs in key in both the events)&amp;nbsp; How can I extact fields for status InputAmountToCredit and ID. I want to sum amount for each Id who is having same status and generate status wise report.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Also my Searches are slow and I want to implement summary index.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;1. I am not sure if tomorrow i want to update my summary index will I be able to do so with new events?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;2. How can I decide what should be part of summary index as right now I have the requirement with these two events only.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;I am new to splunk so any pointers will help&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Thanks for all the support.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Oct 2021 10:40:00 GMT</pubDate>
    <dc:creator>hrishi_deshpand</dc:creator>
    <dc:date>2021-10-20T10:40:00Z</dc:date>
    <item>
      <title>What should I feed to my summary Index? and how Should I extract fields for status, Amount and ID</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-should-I-feed-to-my-summary-Index-and-how-Should-I-extract/m-p/571631#M199198</link>
      <description>&lt;P&gt;&lt;SPAN&gt;INFO | 2021-10-18 05:17 AM | BUSINESS RULE | Payload for ID#: &lt;SPAN class=""&gt;58916&lt;/SPAN&gt; with status Approved is published&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Second Event&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;msg&lt;/SPAN&gt;:&amp;nbsp;&lt;SPAN class=""&gt;&amp;nbsp;INFO | 2021-10-14 10:38 PM |&amp;nbsp; Message consumed: {"InputAmountToCredit":"22.67","CurrencyCode":"AUD","Buid":"1401","OrderNumber":"877118406","Cre ID":"58916"}&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;I want to have sum of InputAmountToCredit based on status . status can vary to different statuses and ID is common field for both the events (but it differs in key in both the events)&amp;nbsp; How can I extact fields for status InputAmountToCredit and ID. I want to sum amount for each Id who is having same status and generate status wise report.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Also my Searches are slow and I want to implement summary index.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;1. I am not sure if tomorrow i want to update my summary index will I be able to do so with new events?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;2. How can I decide what should be part of summary index as right now I have the requirement with these two events only.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;I am new to splunk so any pointers will help&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;Thanks for all the support.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 10:40:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-should-I-feed-to-my-summary-Index-and-how-Should-I-extract/m-p/571631#M199198</guid>
      <dc:creator>hrishi_deshpand</dc:creator>
      <dc:date>2021-10-20T10:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: What should I feed to my summary Index? and how Should I extract fields for status, Amount and ID</title>
      <link>https://community.splunk.com/t5/Splunk-Search/What-should-I-feed-to-my-summary-Index-and-how-Should-I-extract/m-p/571673#M199207</link>
      <description>&lt;P&gt;Give this a try&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(base search to fetch event1) OR (base search to fetch event2)
| rex "ID\#\:\s*(?&amp;lt;ID1&amp;gt;\d+) with status (?&amp;lt;Status&amp;gt;\w+)"
| rex "ID\"\:\"(?&amp;lt; ID2&amp;gt;[^\"]+)"
| rex "InputAmountToCredit\"\:\"(?&amp;lt;InputAmountToCredit&amp;gt;[^\"]+)"
| eval ID=coalesce(ID1,ID2)
| stats latest(Status) as Status values(InputAmountToCredit) as InputAmountToCredit by ID
| where Status="Approved"&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 20 Oct 2021 14:36:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/What-should-I-feed-to-my-summary-Index-and-how-Should-I-extract/m-p/571673#M199207</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2021-10-20T14:36:58Z</dc:date>
    </item>
  </channel>
</rss>

