Knowledge Management

INDEXED_EXTRACTIONS on summary events?

vbumgarner
Contributor

It would be really cool to be able to have all of the fields in a summary index automatically converted to indexed fields. You could then use tstats against a summary index directly with significant speed increases.

Has anyone attempted this?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you create a data model for your summary index and accelerate it, you can use tstats on the SI.

---
If this reply helps you, Karma would be appreciated.
0 Karma

vbumgarner
Contributor

Yes, that’s what I do now, but it has an added delay, extra overhead, etc.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...