Knowledge Management

Unable to save summary search because summary index is missing

Champion

Our summary index is not recognized in UI when attempt to save a scheduled search to write to it. These indexes are just like any other index.

ERROR SavedSearchAdminHandler - Index name=summary_test does not exist. The summary index must exist in order for a scheduled search to populate it.

False. The index exists.

We use a SH_POOL and Distributed search. Summary indexed data will go to indexers.

We are being told that a "stub" index needs to be created on the SH -- why? Why is Splunk able to write to any other index but not a summary index without a "stub" being created on the SH? It appears to be a bug.

Splunk Employee
Splunk Employee

If the index is created on the indexers, but not on the search-heads, the SH may complain when you are trying to select it.
Quick workaround, define the index on the SH, but forwar the data to the indexer anyway.

Builder

Is this issue still in version 6.3+ ?

0 Karma

Champion

What is the reason for this and where is the documentation that explains the issue?

0 Karma

Splunk Employee
Splunk Employee

This is a current limitation in the Splunk UI.

0 Karma