Knowledge Management

Not getting data from summary index

1200125
Engager

We have created a summary Index in Splunk with a cron schedule to run every 15 minutes but while using that Summary Index ad setting the time as today ,We are not getting any data,WHat could be the reason ?

Labels (1)

woodcock
Esteemed Legend

Even though the Summary Index exists on the Indexers, if you do not have an indexes.conf file on your Search Head that defines Webtop_UCF_Operations then you will NOT be able to write to it. Read from it, yes, but not write. Yes, I am totally serious.

0 Karma

rashi83
Path Finder

What if summary index exists on SH only . Issue is the scheduled search doesn't run every time even with job priority set as Highest. Is this happening because its been run too frequently ?

OR should this summary index be created in Indexer first ?
@woodcock

0 Karma

woodcock
Esteemed Legend

Create a real index on the indexers that will get the data and a fake one on the Search Head that will never get data.

0 Karma

rashi83
Path Finder

@woodcock - that mean scheduled search / report will also need to be scheduled on Indexer itself instead of SH.

Is there any documentation in particular from Splunk about this .

0 Karma

woodcock
Esteemed Legend

NO! Your Search Head should be configured as per best-practices to forward all events to the Indexers. All events from anywhere/everywhere go to Indexers.

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...