Deployment Architecture

Establishing new Summary Index - establishing historical data then running nightly for previous day

lmonahan
Path Finder

I recently created a Summary Index to use with some planned dashboards. To generate the Summary Index I run a report each night with Time Range set to Yesterday, "bucket _time span=day" to summarize each day into one entry, then add it to the Summary Index.

Right now I wish I had more historical data in that Summary Index so I'm wondering if its OK to establish the Summary Index freshly, perhaps with a timeframe of Last 30 Days or Last 45 Days, then the next day update the report schedule to look just for Yesterday and continue on like that.

Labels (1)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

That's fine - funnily enough, exactly what I have been doing today! Your search for back-filling the summary index should probably bin your events by day so that they appear as if they have been collected over the past 45 days

View solution in original post

ITWhisperer
SplunkTrust
SplunkTrust

That's fine - funnily enough, exactly what I have been doing today! Your search for back-filling the summary index should probably bin your events by day so that they appear as if they have been collected over the past 45 days

Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...