Getting Data In

What is a summary index and how can one check whether the summary index gets the data of a particular sourcetype?

pavanae
Builder

My main question is I am trying to check whether the current summary indexes in our environment were getting the data from a particular sourcetype. How can I do that and actually where can i check all the summary indexes?

0 Karma

muebel
SplunkTrust
SplunkTrust

Hi pavanae, the docs here have more information on summary indexing in general : http://docs.splunk.com/Documentation/Splunk/6.5.2/Knowledge/Usesummaryindexing

Concerning the sourcetype, all data that is summary indexed gets the stash sourcetype. The original sourcetype is preserved in the orig_sourcetype fields, and so you could figure out what sourcetypes are being put into summary indexes by running:

sourcetype=stash | stats count by orig_sourcetype

Please let me know if this answers your question!

0 Karma

rkondeti3
Explorer

But the stats count will only work if there is data in the index. How can you tell whether an empty index is a summary index or not?

0 Karma

ddrillic
Ultra Champion

You can check whether it's a "real" index in indexes.conf...

0 Karma

woodcock
Esteemed Legend

Yes, exactly:

index=* sourcetype=stash | stats count BY orig_sourcetype
0 Karma
Get Updates on the Splunk Community!

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...