Knowledge Management

Are there summary index naming convention standards?

cesaccenturefed
Path Finder

So I need to set up a summary index for our reporting team to do our monthly reports. Are there any naming conventions that I need to abide by?

If I name the index "report" or "report_summary", does it matter? Does the name matter when counting against your license? Are events in summary indexes exempt from your license count? How are summary events not counted towards your license?

1 Solution

skoelpin
SplunkTrust
SplunkTrust

I typically add "DO NOT CLICK" as the prefix of the report name so I accidentally don't click it and run another populating search.. Also make sure the permissions are set to private so other users cant run the populating search.

The only thing that will count against your licenses is if you index more data, so "reindexing" your data which was already indexed will not count against your licenses, so your safe to run as many summary indexes as you wish.

View solution in original post

anwarmian
Communicator

You can use the guideline documented in:
https://docs.splunk.com/Documentation/CoE/current/Handbook/Naming

For summary index use:
companyname_purpose_sensitivity_summary naming convention

Example: acme_report_prod_summary
or
yourcompanyname_report_dev_summary

skoelpin
SplunkTrust
SplunkTrust

I typically add "DO NOT CLICK" as the prefix of the report name so I accidentally don't click it and run another populating search.. Also make sure the permissions are set to private so other users cant run the populating search.

The only thing that will count against your licenses is if you index more data, so "reindexing" your data which was already indexed will not count against your licenses, so your safe to run as many summary indexes as you wish.

woodcock
Esteemed Legend

HA! You got that from me! 😆 I am glad to see that it has worked all those years!

skoelpin
SplunkTrust
SplunkTrust

Yes I did!

Naming convention is everything, especially when scaling

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...