Knowledge Management

Summary Index Setup, Now How to Load Old Data?

aferone
Builder

I am using the following query to load firewall data into a summary index I've created:

host="aegis1.grc.nasa.gov" | sitop policy_id

This query runs every 5 minutes and it working well.

However, now, I want to be able to "backfill" data into this summary index, using past firewall data. How is this done? I tried scheduling the query from the beginning of the year, but I'm not sure if it worked.

Any ideas?

Thanks!

Tags (1)
0 Karma
1 Solution

aferone
Builder
0 Karma

aferone
Builder
0 Karma
Get Updates on the Splunk Community!

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...

Adoption of Infrastructure Monitoring at Splunk

  Splunk's Growth Engineering team showcases one of their first Splunk product adoption-Splunk Infrastructure ...

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...