Knowledge Management

what is the difference between "summary index" and alert action "Log Event"?

yutaka1005
Builder

I think both of these function can output alert's result to index.
Then, is the difference only these?

1. "summary index" is not related to license calculation.(But "Log Event" is related to it.)
2. "Log Event" can output event data to other splunk instance.(But "summary index" can't.)

0 Karma
1 Solution

HiroshiSatoh
Champion

サマリーインデックスはインデックスに取り込んだログをサマリーするためのもの。ログイベントは新しいログイベントを生成するためのもの。新しいログを取り込むのでログイベントはライセンスを消費します。

View solution in original post

0 Karma

HiroshiSatoh
Champion

サマリーインデックスはインデックスに取り込んだログをサマリーするためのもの。ログイベントは新しいログイベントを生成するためのもの。新しいログを取り込むのでログイベントはライセンスを消費します。

0 Karma

yutaka1005
Builder

English version of above answer.

The summary index is for summarizing the logs included in the index. Log events are for generating new log events. Log events consume licenses because they capture new logs.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...