Getting Data In

If we have summary indexing running on two indexers, will data from both be combined and then aggregated, or computed individually in each of the indexes?

keerthana_k
Communicator

Hi,

We have a Splunk application with two indexers and we have summary indexing running on both of them. I would like to know how exactly Splunk does the summarization.

  1. Will the data from both indexers be combined and then aggregated?
  2. Or, will the data be computed individually in each of the indexes?
  3. If the second case is true, how accurate will the data be, considering that metrics like average will vary based on the sum and count of data present in each of the individual indexer?
0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

If both indexers are executing summarizing searches on their own data only then the two summaries are independent of each other. Simple counts and sums will remain accurate, averages, dc, etc. should remain accurate when either done properly manually or using sistats.

It'd be easier to maintain and keep accurate if you run the summary search from a search head / job server distributing its search to both indexers and then forwarding its results back to the indexers.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

If both indexers are executing summarizing searches on their own data only then the two summaries are independent of each other. Simple counts and sums will remain accurate, averages, dc, etc. should remain accurate when either done properly manually or using sistats.

It'd be easier to maintain and keep accurate if you run the summary search from a search head / job server distributing its search to both indexers and then forwarding its results back to the indexers.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...