Knowledge Management

Unable to save summary search because summary index is missing

the_wolverine
Champion

Our summary index is not recognized in UI when attempt to save a scheduled search to write to it. These indexes are just like any other index.

ERROR SavedSearchAdminHandler - Index name=summary_test does not exist. The summary index must exist in order for a scheduled search to populate it.

False. The index exists.

We use a SH_POOL and Distributed search. Summary indexed data will go to indexers.

We are being told that a "stub" index needs to be created on the SH -- why? Why is Splunk able to write to any other index but not a summary index without a "stub" being created on the SH? It appears to be a bug.

yannK
Splunk Employee
Splunk Employee

If the index is created on the indexers, but not on the search-heads, the SH may complain when you are trying to select it.
Quick workaround, define the index on the SH, but forwar the data to the indexer anyway.

ben_leung
Builder

Is this issue still in version 6.3+ ?

0 Karma

the_wolverine
Champion

What is the reason for this and where is the documentation that explains the issue?

0 Karma

jrodman
Splunk Employee
Splunk Employee

This is a current limitation in the Splunk UI.

0 Karma
Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...