Knowledge Management

How to build a Splunk alert/report using summary index?

joachimroshan
New Member

Currently I am running the below query to generate a report based on appname,spacename,orgnameand foundation which takes longer to run(for the past 24 hours search). How do I create a summary index to efficiently use this query for faster results?

sourcetype="pcf:log"
| eval report_create_time=strftime(now(), "%Y-%m-%d %H:%M:%S,%3N")
| eval spanID_ = coalesce(span_id, SPAN_ID, x_b3_spanid, spanId)
|stats count(spanID_) AS spanCount by report_create_time cf_app_name, cf_space_name, cf_org_name, foundation

Labels (1)
Tags (1)
0 Karma

HiroshiSatoh
Champion

Populating the summary index with data is easy.

(your search)| collect index=your_summary_index

However, it does not mean faster with data.It is only faster because the search is performed periodically and the results are created in advance.
There are disadvantages such as the need to recover manually if the regular execution fails.

It's a good idea to compare the pros and cons with "Accelerate reports".

I think it's better to "Accelerate reports" that can automatically recover from missing teeth.
https://docs.splunk.com/Documentation/Splunk/8.0.2/Report/Acceleratereports

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...