Knowledge Management

fill_summary_index metrics index , duplicates

imrago
Contributor

We are trying to use the fill_summary_index.py script to backfill times when the data isn't populated in a metrics based index. The script is not detecting gaps, it is re-running the searches for the defined time range.

I would assume  that the issue might be with the default dedupsearch:

dedupsearch = 'search splunk_server=local index=$index$ $namefield$="$name$" | stats count by $timefield$'

which is not compatible with metrics based indexes.

Any recommendations?

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and ...

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and Splunk ES Protecting a ...

It's Customer Success Time at .conf25

Hello Splunkers,   Ready for .conf25? The customer success and experience team is and can’t wait to see you ...

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...