Hi,
We have a Splunk application with two indexers and we have summary indexing running on both of them. I would like to know how exactly Splunk does the summarization.
If both indexers are executing summarizing searches on their own data only then the two summaries are independent of each other. Simple counts and sums will remain accurate, averages, dc, etc. should remain accurate when either done properly manually or using sistats.
It'd be easier to maintain and keep accurate if you run the summary search from a search head / job server distributing its search to both indexers and then forwarding its results back to the indexers.
If both indexers are executing summarizing searches on their own data only then the two summaries are independent of each other. Simple counts and sums will remain accurate, averages, dc, etc. should remain accurate when either done properly manually or using sistats.
It'd be easier to maintain and keep accurate if you run the summary search from a search head / job server distributing its search to both indexers and then forwarding its results back to the indexers.