Getting Data In

Why is there no data in my summary index?

xsstest
Communicator

I built a splunk cluster. I created a lot of alerts on the main search server, some alerts I enabled the summary index, select the summary index for the "alerts", after a long period of time, my index "alerts" no data, why? Is there a problem with my configuration?

alt text

alt text

Tags (1)
0 Karma
1 Solution

xsstest
Communicator

answser:

In a cluster, if you need to create a summary index, it should not be created on the indexer cluster. You should create a summary index on the search head. Because the results of the search will not be written to the indexer cluster, will only write the summary index in the search header, and finally you need to configure the search header to forward the summary index to your index cluster.

中文:在集群中,如果你需要创建摘要索引,不应该在索引集群上创建。你应该在搜索头上创建摘要索引。因为搜索头产生的结果不会写入索引集群,只会写入搜索头中的摘要索引,最后你需要配置搜索头将摘要索引转发到你的索引集群里。

View solution in original post

0 Karma

xsstest
Communicator

answser:

In a cluster, if you need to create a summary index, it should not be created on the indexer cluster. You should create a summary index on the search head. Because the results of the search will not be written to the indexer cluster, will only write the summary index in the search header, and finally you need to configure the search header to forward the summary index to your index cluster.

中文:在集群中,如果你需要创建摘要索引,不应该在索引集群上创建。你应该在搜索头上创建摘要索引。因为搜索头产生的结果不会写入索引集群,只会写入搜索头中的摘要索引,最后你需要配置搜索头将摘要索引转发到你的索引集群里。

0 Karma

lguinn2
Legend

What was the search? Unless something was actually output to the summary index, it will be empty.

You must use commands like sistats, sichart, sitimechart, collect to put data into the summary index.
You might want to review the documentation on summary indexing here.

0 Karma

xsstest
Communicator

I create an "alerts" index, and then in some of the alert to enabled the summary index to "alerts". This two-step setup is done. Is there a problem with this

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...