Deployment Architecture

./splunk cmd python fill_summary_index.py -app splunkdotcom -name "*" -et -mon@mon -lt @mon -dedup true -auth admin:changeme

Prakash493
Communicator

Hi , Currently we have infrastructure with one search head deployer , one indexer cluster , one deployment server with 3 sh , 6 idx. we are trying to backfill the data through summary indexing , when i check the splunk docs i found a command ./splunk cmd python fill_summary_index.py -app splunkdotcom -name "*" -et -mon@mon -lt @mon -dedup true -auth admin:changeme, but confused on which location i have to execute this command as we have a indexer cluster in one server and search head deployer in one server , if in indexer cluster master , on which location simply in bin folder or do i need to go to the app name and inside the app their is bin folder , their ? after executing in indexer cluster master is it pull the changes to search head ? or do i need to execute it on sh deployer too.

Please help me

Tags (1)
0 Karma
1 Solution

woodcock
Esteemed Legend

The summary index backfill script must be run on any Search Head.

View solution in original post

0 Karma

woodcock
Esteemed Legend

The summary index backfill script must be run on any Search Head.

0 Karma

Prakash493
Communicator

But my search heads are clustered and have one search head deployer that I use to deploy apps , so you mean just I run this command only on any one search head right ?

0 Karma

woodcock
Esteemed Legend

That is correct.

0 Karma

Prakash493
Communicator

does it create any issues if i run this script on search head , i mean any performance issues ?

0 Karma
Get Updates on the Splunk Community!

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...