Splunk Search

How to schedule daily summary indexing with a search that uses the geostats command? Is there another approach?

cheinlein
Engager

My search is simple:

sourcetype=log_data | iplocation c_ip | geostats latfield=lat longfield=lon count

but I have a lot of data, about 100,000,000 logs a day, and the customer wants a monthly summary. A monthly search would be too slow. I'd like to be able to write a daily summary and schedule it, but there is no summary indexing for the geostats command. (sigeostats ). Ideas on another way to approach this?

0 Karma

knielsen
Contributor

You don't need the si commands at all to populate a summary index. Your search works fine as a daily search for that. Well, it depends on what you do with the data later on. I have about 200 summary indexes in place, I never even tried the si commands, they are all built by searches using stats.

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...