Getting Data In

How to move a summary index from a search head to the indexers?

Glasses
Builder

Hi
I don't have a lot of experience with summary indexes, but the previous admin created some schedule reports and set summary indexing to an index on the local search head box.

I have to decom this physical server and move the searchhead to the cloud, so I will tar it and move it.

But I don't want the summary index - indexing locally to an instance that is a dedicated searchhead...

Please advise how I can configure the summary to send to the indexers (which are non-clustered, autolb).
Thank you

0 Karma
1 Solution

Glasses
Builder

Thank you, one quick follow up,
do I create these confs in system/local or in the search app or launcher app where I find the base schedule searches... not sure which directory to insert those...

Thanks

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...