Knowledge Management

Schedule automatic summary backfill?

the_wolverine
Champion

I'd like to have summary backfill run on a scheduled basis to fill in the gaps automatically. I'd probably run this during non-peak hours to reduce any impact on the servers.

How can this be done?

inventsekar
SplunkTrust
SplunkTrust

http://docs.splunk.com/Documentation/Splunk/6.4.2/Knowledge/Managesummaryindexgapsandoverlaps
Use the backfill script to add other data or fill summary index gaps
The fill_summary_index.py script backfills gaps in summary index collection by
running the saved searches that populate the summary index as they would have
been executed at their regularly scheduled times for a given time range.

check this one as well.. FYI - This document refers to 3.x versions of Splunk.
http://wiki.splunk.com/Community:Summary_Indexing_Back_Fill

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

pradeepkumarg
Influencer

Did you get around with this?

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...