Knowledge Management

Summary Index Backfill

kenchisho
Path Finder

Hi guys,

I am trying to backfill data into a summary index...

when i run the command using the py script i get an error saying:

*** For saved search 'fw_web_monthly_top_domains' ***
No scheduled times for your time range.

I have turned off the schedule for this search and tried playing around with the et and lt values with no effect...

any ideas?

Tags (2)
0 Karma

clyde772
Communicator

kenchisho,

Make sure to check the few things,

  1. Saved search should have a proper scheduling set-up, ie */5 * * * * or every X.
  2. Make sure that perticular saved search have proper authrization setup to share, default splunk seems to save it as private search so it can't be shared.

Clyde772.

0 Karma

kenchisho
Path Finder

the schedule is set to run at midnight on the first day of every month...

0 0 1 * *

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

what is the schedule for 'fw_web_monthly_top_domains'?

0 Karma

kenchisho
Path Finder

Hi... here is the complete command...

./splunk cmd python fill_summary_index.py -app noc -index firewall_summary -name fw_web_monthly_top_domain -et -1mon@mon -lt @mon -j 8 -owner admin -showprogress true -auth admin:changeme

0 Karma

imrago
Contributor

please post the complete command

0 Karma
Get Updates on the Splunk Community!

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...

Splunk Lantern | Spotlight on Security: Adoption Motions, War Stories, and More

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...