Dashboards & Visualizations

Real-time search... on a summary index?

Motivator

What is the behavior if you set up a dashboard that creates a graph using a realtime search, but is using a summary index, say populated every 15 sec? Would this work as I expect it to (events would appear on the graph as they were added to the summary index by the scheduled search) ?

1 Solution

Splunk Employee
Splunk Employee

There's no reason that you can't run a real time search on data going into a summary index. That said, since the scheduler runs no more frequently than every minute, you'll see >15s latency.

View solution in original post

0 Karma

Splunk Employee
Splunk Employee

There's no reason that you can't run a real time search on data going into a summary index. That said, since the scheduler runs no more frequently than every minute, you'll see >15s latency.

View solution in original post

0 Karma

Motivator

Ah, yes I had overlooked that even cron notation * * * * * would be run only every minute. Thanks!

0 Karma

Motivator

Haven't tried it yet, was wondering if someone had an answer.

0 Karma

Splunk Employee
Splunk Employee

What happens when you try it?

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!