Knowledge Management

Summary index not showing in drop down

rohitvjoshi
Path Finder

Hi Team,

We have to create the Summary index , as per process we have created an index called si_test in indexes.conf in cluster master and pushed into indexers.After Rolling restart i have checked the Indexes via Monitoring Console i can see the index name.

In SH i want to use that summary index, I have select the Scheduled report and select "Edit Summary index" and checked the enable summary indexing but i am not able to see the summary index created by us "SI_test".

Am i missing anything, as i remember we have to do some setting in SH also but not able to recollect the same.

Note:We having Multisite cluster env.

Thanks In Advance 🙂

0 Karma
1 Solution

rohitvjoshi
Path Finder

Hi Team,

I am able to see the Summary index in the drop-down list, Below the steps, we have to follow to deploy the summary index:

  1. We have to add a new stanza in indexes.conf file in CM & Then we have to push the configuration bundle to all peers.
  2. We have to push the same index via Deployer to SH cluster, Add the same stanza in indexes.conf file available in Deployer.
  3. Once the new index is there push the configuration bundle using below command: ./splunk apply shcluster-bundle -target :

View solution in original post

rohitvjoshi
Path Finder

Hi Team,

I am able to see the Summary index in the drop-down list, Below the steps, we have to follow to deploy the summary index:

  1. We have to add a new stanza in indexes.conf file in CM & Then we have to push the configuration bundle to all peers.
  2. We have to push the same index via Deployer to SH cluster, Add the same stanza in indexes.conf file available in Deployer.
  3. Once the new index is there push the configuration bundle using below command: ./splunk apply shcluster-bundle -target :

harsmarvania57
Ultra Champion

Hi,

You need to create same index on Search Head as well for summary indexing.

Thanks,
Harshil

0 Karma

rohitvjoshi
Path Finder

I am having 3 sh ,so i have to do this in all SH or we can push via CM?

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...