Deployment Architecture

Establishing new Summary Index - establishing historical data then running nightly for previous day

lmonahan
Path Finder

I recently created a Summary Index to use with some planned dashboards. To generate the Summary Index I run a report each night with Time Range set to Yesterday, "bucket _time span=day" to summarize each day into one entry, then add it to the Summary Index.

Right now I wish I had more historical data in that Summary Index so I'm wondering if its OK to establish the Summary Index freshly, perhaps with a timeframe of Last 30 Days or Last 45 Days, then the next day update the report schedule to look just for Yesterday and continue on like that.

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

That's fine - funnily enough, exactly what I have been doing today! Your search for back-filling the summary index should probably bin your events by day so that they appear as if they have been collected over the past 45 days

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

That's fine - funnily enough, exactly what I have been doing today! Your search for back-filling the summary index should probably bin your events by day so that they appear as if they have been collected over the past 45 days

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...