Splunk Dev

How to remove events from each summary index and backfill using fill_summary_index.py for a particular time period?

manja054
Explorer

Hi,

I am new to summary indexes.

I have scenario to work with.

i have summary index searches for 1min, 5min,1hr,and a day. My 1min & 5min indexes have events from main index and 1 hr summary index is based on 5min summary index and for 1day its based on an hour summary index.

i want to remove events from each summary index mentioned above for the period of 4\5\2016 22:00 to 4\8\2016 14:43 and back fill the same using fill_summary_index.py. (My deployment server was down on that particular time)

Can anyone help me how can i achieve this without duplication of events please?

0 Karma

somesoni2
Revered Legend

Information on How to delete data
http://docs.splunk.com/Documentation/Splunk/6.4.3/Indexer/RemovedatafromSplunk#Delete_events_from_su...

How to backfill summary index
http://docs.splunk.com/Documentation/Splunk/6.4.3/Knowledge/Managesummaryindexgapsandoverlaps#Use_th...

Make sure that, in both steps, you're using same time range (The time range of backfill script should be in a way that it reloads deleted data.)

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...