We have created a summary Index in Splunk with a cron schedule to run every 15 minutes but while using that Summary Index ad setting the time as today ,We are not getting any data,WHat could be the reason ?
Even though the Summary Index
exists on the Indexers
, if you do not have an indexes.conf
file on your Search Head
that defines Webtop_UCF_Operations
then you will NOT be able to write to it. Read from it, yes, but not write. Yes, I am totally serious.
What if summary index exists on SH only . Issue is the scheduled search doesn't run every time even with job priority set as Highest. Is this happening because its been run too frequently ?
OR should this summary index be created in Indexer first ?
@woodcock
Create a real index on the indexers that will get the data and a fake one on the Search Head that will never get data.
@woodcock - that mean scheduled search / report will also need to be scheduled on Indexer itself instead of SH.
Is there any documentation in particular from Splunk about this .
NO! Your Search Head should be configured as per best-practices to forward all events to the Indexers. All events from anywhere/everywhere go to Indexers.