Splunk Dev

How to remove events from each summary index and backfill using fill_summary_index.py for a particular time period?

manja054
Explorer

Hi,

I am new to summary indexes.

I have scenario to work with.

i have summary index searches for 1min, 5min,1hr,and a day. My 1min & 5min indexes have events from main index and 1 hr summary index is based on 5min summary index and for 1day its based on an hour summary index.

i want to remove events from each summary index mentioned above for the period of 4\5\2016 22:00 to 4\8\2016 14:43 and back fill the same using fill_summary_index.py. (My deployment server was down on that particular time)

Can anyone help me how can i achieve this without duplication of events please?

0 Karma

somesoni2
Revered Legend

Information on How to delete data
http://docs.splunk.com/Documentation/Splunk/6.4.3/Indexer/RemovedatafromSplunk#Delete_events_from_su...

How to backfill summary index
http://docs.splunk.com/Documentation/Splunk/6.4.3/Knowledge/Managesummaryindexgapsandoverlaps#Use_th...

Make sure that, in both steps, you're using same time range (The time range of backfill script should be in a way that it reloads deleted data.)

0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...