Knowledge Management

How do you create a summary index?

1dbenzo
Explorer

Hello, can anybody tell me how to "create a summary index"?

Tags (1)

skulk
Explorer

Pretty good intro in Summary Indexes
https://www.splunk.com/view/SP-CAAACZW

0 Karma

_d_
Splunk Employee
Splunk Employee

To create an index (whether or not it will be used for summaries does not matter) follow the instructions here:

Set up multiple indexes

0 Karma

Ayn
Legend

therealdpk
Path Finder

The documentation is not very clear on one point: It says you simply run "eventtype = firewall | stop src_ip" and that creates a summary index named "summary". Where did that name come from and what if I want two summary indexes to exist?

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...