Getting Data In

How do I know the title of my system index

aohls
Contributor

I have read through the documentation and still feel that I am missing something with creating an index summary. I want to use sistats and have my data setup how I want it to generate the index summary. How would I know what the summary is named or how do I generate an index summary for where my data will get stored. I might have missed a key point but I done see how if I use sistats I know how to reference my data.

0 Karma
1 Solution

adonio
Ultra Champion

a summary index is just like any other index
for creating, setting, and all other purposes

View solution in original post

0 Karma

adonio
Ultra Champion

a summary index is just like any other index
for creating, setting, and all other purposes

0 Karma

aohls
Contributor

So at the end of the search if I have sistats. How would I then search that index? I might need to read up on indexing more but I am looking to speed searching the data. Using sistats seems that it would allow me to search just that data but I am not sure how I would then search it after. Is it more of a behind the scenes item where my search will simply be faste?

0 Karma

aohls
Contributor

@adonio thank you. I checked these before and it clicked better this time. Will this persist data also? We have about a 3 month limit. I am creating a manual dataset to persist for a longer timerange. Do indexes keep data longer also or only accelerate reporting?

0 Karma

adonio
Ultra Champion

you can set index to whatever retention period you want
retention is limited by either time or size, whatever comes first

0 Karma

aohls
Contributor

This makes a lot more sense thank you. I think half the confusion has come from me not having the access to create an index.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...