Hello,
I tried to research whether it is possible or not to use summary indexing in Splunk Free, but I didn't find any good answers.
I know that summary indexing with the help of Splunk Web or with the help of summary indexing transforming commands in not available for Splunk free version. Also I tried using collect command, but that didn't work either.
Can anyone tell me if it's possible to use summary indexing and if yes, how to do that?
Thanks!
No.
The summary techniques require scheduled searches, and splunk free does not have the scheduling feature
No.
The summary techniques require scheduled searches, and splunk free does not have the scheduling feature