Pretty good intro in Summary Indexes
https://www.splunk.com/view/SP-CAAACZW
To create an index (whether or not it will be used for summaries does not matter) follow the instructions here:
The Knowledge Manager Manual has excellent information on this:
http://www.splunk.com/base/Documentation/4.2/Knowledge/Usesummaryindexing
http://www.splunk.com/base/Documentation/4.2/Knowledge/Configuresummaryindexes
The documentation is not very clear on one point: It says you simply run "eventtype = firewall | stop src_ip" and that creates a summary index named "summary". Where did that name come from and what if I want two summary indexes to exist?