Deployment Architecture

./splunk cmd python fill_summary_index.py -app splunkdotcom -name "*" -et -mon@mon -lt @mon -dedup true -auth admin:changeme

Prakash493
Communicator

Hi , Currently we have infrastructure with one search head deployer , one indexer cluster , one deployment server with 3 sh , 6 idx. we are trying to backfill the data through summary indexing , when i check the splunk docs i found a command ./splunk cmd python fill_summary_index.py -app splunkdotcom -name "*" -et -mon@mon -lt @mon -dedup true -auth admin:changeme, but confused on which location i have to execute this command as we have a indexer cluster in one server and search head deployer in one server , if in indexer cluster master , on which location simply in bin folder or do i need to go to the app name and inside the app their is bin folder , their ? after executing in indexer cluster master is it pull the changes to search head ? or do i need to execute it on sh deployer too.

Please help me

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

The summary index backfill script must be run on any Search Head.

View solution in original post

0 Karma

woodcock
Esteemed Legend

The summary index backfill script must be run on any Search Head.

0 Karma

Prakash493
Communicator

But my search heads are clustered and have one search head deployer that I use to deploy apps , so you mean just I run this command only on any one search head right ?

0 Karma

woodcock
Esteemed Legend

That is correct.

0 Karma

Prakash493
Communicator

does it create any issues if i run this script on search head , i mean any performance issues ?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Introduction to Splunk AI

How are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. Lucky for ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Maximizing the Value of Splunk ES 8.x

Splunk Enterprise Security (ES) continues to be a leader in the Gartner Magic Quadrant, reflecting its pivotal ...