Splunk Search

How to schedule daily summary indexing with a search that uses the geostats command? Is there another approach?

cheinlein
Engager

My search is simple:

sourcetype=log_data | iplocation c_ip | geostats latfield=lat longfield=lon count

but I have a lot of data, about 100,000,000 logs a day, and the customer wants a monthly summary. A monthly search would be too slow. I'd like to be able to write a daily summary and schedule it, but there is no summary indexing for the geostats command. (sigeostats ). Ideas on another way to approach this?

0 Karma

knielsen
Contributor

You don't need the si commands at all to populate a summary index. Your search works fine as a daily search for that. Well, it depends on what you do with the data later on. I have about 200 summary indexes in place, I never even tried the si commands, they are all built by searches using stats.

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...