Splunk Search

How to capture older data through Summary Index Populating Search?

Path Finder

Hi

If I have a summary-populating-index search that is scheduled to run daily. Is it possible to index data that is older than a day & goes back about a year through this search?

Thanks for your help.

Ranga

0 Karma
1 Solution

Splunk Employee
Splunk Employee

You can use the backfilling tool:

http://www.splunk.com/base/Documentation/latest/Knowledge/Managesummaryindexgapsandoverlaps

The script will run searches over the appropriate time range and will back fill the summary index.

View solution in original post

Champion

Splunk ships with a script, fill_summary_index.py, that does this for you.

Splunk Employee
Splunk Employee

You can use the backfilling tool:

http://www.splunk.com/base/Documentation/latest/Knowledge/Managesummaryindexgapsandoverlaps

The script will run searches over the appropriate time range and will back fill the summary index.

View solution in original post

Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!