Knowledge Management

How do I test whether the summary index is working?

mike7860
Explorer

I have scheduled a search an saved it in a summary index. How do I test whether the results that I had saved in summary index works? Please let me know. There is a documentation available online but I am unable to understand it.

Tags (1)
0 Karma

okrabbe_splunk
Splunk Employee
Splunk Employee

Mike,

If you used the default index for summary indexing when you set up your search you can easily do a search like the one below:

index=summary search_name="My Saved Search name"

You should then see your data.

0 Karma

mike7860
Explorer

So will the result be displayed as events? The result is in the form of a table. So will the result be displayed as events or will a table be populated.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...