Knowledge Management

Why does a Summary Index use the "main" index when I specified a different index?

halbeisendv
Path Finder

Why does a Summary Index use the "main" index when I specified a completely different index? I have looked in inputs.conf and savedsearches.conf and cannot determine why/how the main index is being used. To be fair, we initially used main, but then decided to go with a completed different index name. Main still receives data and so does the new index.

0 Karma

JimGat_SSI
New Member

halbeisendv,

Have you made any progress on this issue? What version are you on? Are you on a Search Cluster?

I cannot find what is causing the behavior as it is seemingly very random.

0 Karma

pruthvikrishnap
Contributor

Hi,
Data will land in the index mentioned in .conf files only, can you rechek or you can troubleshoot using "btool" command,
https://www.splunk.com/blog/2012/10/02/tips-and-tricks-for-the-new-guy.html

0 Karma

halbeisendv
Path Finder

btool does not locate an inputs file with a reference to the main index.

0 Karma

JimGat_SSI
New Member

halbeisendv,

Have you found a resolution to the issue?

I am seeing a similar issue but it seems to be random (not consistent behavior at all)

What version are you dealing with? Is it a search cluster?

0 Karma

halbeisendv
Path Finder

Hello JimGat_SSI: I think the resolution was that the stash sourcetype uses the main index -- not that I like that either, but now I know why I am seeing information in "main."

0 Karma

DavidHourani
Super Champion

@halbeisendv please share the config you have in saved search. How are you redirecting to main index ? Are you using the collect command ?

0 Karma

adonio
Ultra Champion

it is un clear from your question if you mean to data being generated by a search and written to an index - meaning "summarized data", or to data that lands in splunk right from the source - "indexed data". by default, main is the default index if no other index is specified in inputs.conf. summary (the index) is the default summary index if no other index is specified in savedsearches.conf.
which one is it?

0 Karma

halbeisendv
Path Finder

I mean the former -- data being generated by a search and written to a summary index. I suspect a user initially selected the main index to write to, but then changed their mind. So now, we have summary data being written to a new index and the main index. The problem is, I cannot find any reference to the main index.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...