Knowledge Management

Having difficulty using the results from my Summary Index to do a search in

hrached
Loves-to-Learn

Hello 
I'm trying to create a summary index. I scheduled a search and edited the summary index but I could not do the new search in the results that I have already obtained in the scheduled searches 

Labels (1)
0 Karma

hrached
Loves-to-Learn

I have already an index and I selected it as summary index.
But after the scheduled research run I make a research about this index but I have always 0 event while the results of research isn't 0 event

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hrached,

could you share the scheduled search?

Ciao.

Giuseppe

0 Karma

hrached
Loves-to-Learn

hrached_0-1647362725246.png

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hrached,

ok, at the end of the scheduled search you have to add:

  • a table command listing all the fields you want in your summary index,
  • a collect command.

The command that adds the search results to the summary index is "collect" that's missing in your search.

As you can read at https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Collect, you have to add at the end of your search:

your_search
| collect index=your_summary_index

in this way your search results will be in the summary index.

Ciao.

Giuseppe

0 Karma

hrached
Loves-to-Learn

hrached_0-1647363442484.png

I have already do that I think 


 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @hrached,

as you can read at https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Setupsummaryindexes and https://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Configuresummaryindexes to use a summary index you have to:

  • manually create a summary index using GUI or indexes.conf file,
  • create a streaming search (a search with streaming commands as stats, timechart or able or others, in otehr words, not row events) to populate it, remembering to add at the end of the search the collect command,
  • schedule the search.

In this way you'll have the search results in the summary index.

What's the problem you encountered?

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...