Knowledge Management

Summary index not showing in drop down

rohitvjoshi
Path Finder

Hi Team,

We have to create the Summary index , as per process we have created an index called si_test in indexes.conf in cluster master and pushed into indexers.After Rolling restart i have checked the Indexes via Monitoring Console i can see the index name.

In SH i want to use that summary index, I have select the Scheduled report and select "Edit Summary index" and checked the enable summary indexing but i am not able to see the summary index created by us "SI_test".

Am i missing anything, as i remember we have to do some setting in SH also but not able to recollect the same.

Note:We having Multisite cluster env.

Thanks In Advance 🙂

0 Karma
1 Solution

rohitvjoshi
Path Finder

Hi Team,

I am able to see the Summary index in the drop-down list, Below the steps, we have to follow to deploy the summary index:

  1. We have to add a new stanza in indexes.conf file in CM & Then we have to push the configuration bundle to all peers.
  2. We have to push the same index via Deployer to SH cluster, Add the same stanza in indexes.conf file available in Deployer.
  3. Once the new index is there push the configuration bundle using below command: ./splunk apply shcluster-bundle -target :

View solution in original post

rohitvjoshi
Path Finder

Hi Team,

I am able to see the Summary index in the drop-down list, Below the steps, we have to follow to deploy the summary index:

  1. We have to add a new stanza in indexes.conf file in CM & Then we have to push the configuration bundle to all peers.
  2. We have to push the same index via Deployer to SH cluster, Add the same stanza in indexes.conf file available in Deployer.
  3. Once the new index is there push the configuration bundle using below command: ./splunk apply shcluster-bundle -target :

harsmarvania57
Ultra Champion

Hi,

You need to create same index on Search Head as well for summary indexing.

Thanks,
Harshil

0 Karma

rohitvjoshi
Path Finder

I am having 3 sh ,so i have to do this in all SH or we can push via CM?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...