Knowledge Management

Summary index not showing in drop down

rohitvjoshi
Path Finder

Hi Team,

We have to create the Summary index , as per process we have created an index called si_test in indexes.conf in cluster master and pushed into indexers.After Rolling restart i have checked the Indexes via Monitoring Console i can see the index name.

In SH i want to use that summary index, I have select the Scheduled report and select "Edit Summary index" and checked the enable summary indexing but i am not able to see the summary index created by us "SI_test".

Am i missing anything, as i remember we have to do some setting in SH also but not able to recollect the same.

Note:We having Multisite cluster env.

Thanks In Advance 🙂

0 Karma
1 Solution

rohitvjoshi
Path Finder

Hi Team,

I am able to see the Summary index in the drop-down list, Below the steps, we have to follow to deploy the summary index:

  1. We have to add a new stanza in indexes.conf file in CM & Then we have to push the configuration bundle to all peers.
  2. We have to push the same index via Deployer to SH cluster, Add the same stanza in indexes.conf file available in Deployer.
  3. Once the new index is there push the configuration bundle using below command: ./splunk apply shcluster-bundle -target :

View solution in original post

Anders_S
Engager

Summary index not showing in drop down happened to us due to WLM and all-time search restriction

0 Karma

rohitvjoshi
Path Finder

Hi Team,

I am able to see the Summary index in the drop-down list, Below the steps, we have to follow to deploy the summary index:

  1. We have to add a new stanza in indexes.conf file in CM & Then we have to push the configuration bundle to all peers.
  2. We have to push the same index via Deployer to SH cluster, Add the same stanza in indexes.conf file available in Deployer.
  3. Once the new index is there push the configuration bundle using below command: ./splunk apply shcluster-bundle -target :

harsmarvania57
Ultra Champion

Hi,

You need to create same index on Search Head as well for summary indexing.

Thanks,
Harshil

0 Karma

rohitvjoshi
Path Finder

I am having 3 sh ,so i have to do this in all SH or we can push via CM?

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

 Ready to master Kubernetes and cloud monitoring like the pros? Join Splunk’s Growth Engineering team for an ...