Getting Data In

How to create a summary index for my csv file

JoshuaJohn
Contributor

On a daily basis I have a CSV loaded into splunk. I want to create a summary index so that this CSV will have historical data. Currently this file overwrites itself daily.

I have access to savedsearches.conf

Is there a tutorial for this somewhere, or a template I can follow?

0 Karma

somesoni2
Revered Legend

This should give you details of summary indexing process.
http://docs.splunk.com/Documentation/SplunkCloud/6.6.0/Knowledge/Usesummaryindexing#Set_up_summary_i...

Again, the traditional use for summary indexing is for optimizing searches/reports/dashboards, but it can be used for your use-case. You don't have to use any SI commands, so you can use use the like this (assuming CSV you upload as lookup)

| inputlookup yourUploadeda.csv 
0 Karma

adonio
Ultra Champion
0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...