Knowledge Management

Not getting data from summary index

1200125
Engager

We have created a summary Index in Splunk with a cron schedule to run every 15 minutes but while using that Summary Index ad setting the time as today ,We are not getting any data,WHat could be the reason ?

Labels (1)

woodcock
Esteemed Legend

Even though the Summary Index exists on the Indexers, if you do not have an indexes.conf file on your Search Head that defines Webtop_UCF_Operations then you will NOT be able to write to it. Read from it, yes, but not write. Yes, I am totally serious.

0 Karma

rashi83
Path Finder

What if summary index exists on SH only . Issue is the scheduled search doesn't run every time even with job priority set as Highest. Is this happening because its been run too frequently ?

OR should this summary index be created in Indexer first ?
@woodcock

0 Karma

woodcock
Esteemed Legend

Create a real index on the indexers that will get the data and a fake one on the Search Head that will never get data.

0 Karma

rashi83
Path Finder

@woodcock - that mean scheduled search / report will also need to be scheduled on Indexer itself instead of SH.

Is there any documentation in particular from Splunk about this .

0 Karma

woodcock
Esteemed Legend

NO! Your Search Head should be configured as per best-practices to forward all events to the Indexers. All events from anywhere/everywhere go to Indexers.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...