Knowledge Management

Not getting data from summary index

1200125
Engager

We have created a summary Index in Splunk with a cron schedule to run every 15 minutes but while using that Summary Index ad setting the time as today ,We are not getting any data,WHat could be the reason ?

Labels (1)

woodcock
Esteemed Legend

Even though the Summary Index exists on the Indexers, if you do not have an indexes.conf file on your Search Head that defines Webtop_UCF_Operations then you will NOT be able to write to it. Read from it, yes, but not write. Yes, I am totally serious.

0 Karma

rashi83
Path Finder

What if summary index exists on SH only . Issue is the scheduled search doesn't run every time even with job priority set as Highest. Is this happening because its been run too frequently ?

OR should this summary index be created in Indexer first ?
@woodcock

0 Karma

woodcock
Esteemed Legend

Create a real index on the indexers that will get the data and a fake one on the Search Head that will never get data.

0 Karma

rashi83
Path Finder

@woodcock - that mean scheduled search / report will also need to be scheduled on Indexer itself instead of SH.

Is there any documentation in particular from Splunk about this .

0 Karma

woodcock
Esteemed Legend

NO! Your Search Head should be configured as per best-practices to forward all events to the Indexers. All events from anywhere/everywhere go to Indexers.

0 Karma
Get Updates on the Splunk Community!

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...

The Visibility Gap: Hybrid Networks and IT Services

The most forward thinking enterprises among us see their network as much more than infrastructure – it's their ...

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...