Dashboards & Visualizations

How to use summary indexing in dashboards?

splunker9999
Path Finder

Hi,

I am new to Summary Indexing. Can you please let me know how to use summary indexing in dashboards?

From documentation, we can enable this for reports or alerts, but how can we enable this for dashboards?

Thanks

0 Karma
1 Solution

pradeepkumarg
Influencer

Summary indexing works on the data layer and not on dashboards.

You summarize your raw data into an aggregated form and store in a seperate index so that your dashboard searches runs faster on a pre aggregated, less amount of data when compared to raw data

http://docs.splunk.com/Documentation/Splunk/6.4.2/Knowledge/Usesummaryindexing

If you want to do it at search/report level instead of data level, You can use Report Acceleration where splunk itself runs the summary for your dashboard search behind the scenes. There are few restrictions though.

http://docs.splunk.com/Documentation/Splunk/6.4.2/Report/Acceleratereports

View solution in original post

pradeepkumarg
Influencer

Summary indexing works on the data layer and not on dashboards.

You summarize your raw data into an aggregated form and store in a seperate index so that your dashboard searches runs faster on a pre aggregated, less amount of data when compared to raw data

http://docs.splunk.com/Documentation/Splunk/6.4.2/Knowledge/Usesummaryindexing

If you want to do it at search/report level instead of data level, You can use Report Acceleration where splunk itself runs the summary for your dashboard search behind the scenes. There are few restrictions though.

http://docs.splunk.com/Documentation/Splunk/6.4.2/Report/Acceleratereports

splunker9999
Path Finder

So, do we need to initially set up a reports and enable summary indexing on that report to use this for dashboards?

0 Karma

pradeepkumarg
Influencer

Right, you set up a search whose results you want to summarize, schedule it and select Enable Summary indexing and give a report name of your choice and index of your choice to send the data to. And then change your dashboard searches to search for the data in the summary index than the raw index.

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...