Knowledge Management

Summary Index Backfill

kenchisho
Path Finder

Hi guys,

I am trying to backfill data into a summary index...

when i run the command using the py script i get an error saying:

*** For saved search 'fw_web_monthly_top_domains' ***
No scheduled times for your time range.

I have turned off the schedule for this search and tried playing around with the et and lt values with no effect...

any ideas?

Tags (2)
0 Karma

clyde772
Communicator

kenchisho,

Make sure to check the few things,

  1. Saved search should have a proper scheduling set-up, ie */5 * * * * or every X.
  2. Make sure that perticular saved search have proper authrization setup to share, default splunk seems to save it as private search so it can't be shared.

Clyde772.

0 Karma

kenchisho
Path Finder

the schedule is set to run at midnight on the first day of every month...

0 0 1 * *

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

what is the schedule for 'fw_web_monthly_top_domains'?

0 Karma

kenchisho
Path Finder

Hi... here is the complete command...

./splunk cmd python fill_summary_index.py -app noc -index firewall_summary -name fw_web_monthly_top_domain -et -1mon@mon -lt @mon -j 8 -owner admin -showprogress true -auth admin:changeme

0 Karma

imrago
Contributor

please post the complete command

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...