Knowledge Management

Summary Index Limitations

cwinkler109
New Member

Hello,

I am using a summary index to track a handful of our key metrics per day over time. I am using the summary index for the purposes of improving search response times of panels on some of our dashboards.

The data in the summary index contains daily averages and counts per customer for 8 of our KPI’s. The events are written across 8 different sources in our summary index. About 600k total events are being written to the summary index each day. Are there any performance/capacity repercussions to this? From what I understand the summary index has no data retention limitations. Is 600k events per day in the summary index acceptable? We are using Splunk Cloud.

Thanks,
Chris

0 Karma

adonio
Ultra Champion

summary index is just like any other index
its limited by the configurations you set in indexes.conf (also via ui)
retention, size and other parameters are set by you

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...