Splunk Search

Summary Indexing and Send data back to Indexers

nikhilmehra79
Path Finder

Hi,

I have build a dedicated Search head for running scheduled search and get summary indexing data, now i think it is recommended to send the summary indexed data back to indexers.How do we do this?

I have build a new index of 50 MB on this dedicated search head called si_summary. This is getting populated on this search head , but it never created same si_summary on my 2 indexers automatically.
So i manually created si_summary on 2 indexers but they still not populated with any data...any idea i am doing anything wrong. I am assuming job of summary indexer search head is to save summary data but that should not be stored on search head rather should be passed to indexer correct?

0 Karma
1 Solution

sbrant_splunk
Splunk Employee
Splunk Employee

You will need to have an outputs.conf on your search head, to let it know where to forward data:

http://docs.splunk.com/Documentation/Splunk/latest/admin/Outputsconf

View solution in original post

sbrant_splunk
Splunk Employee
Splunk Employee

You will need to have an outputs.conf on your search head, to let it know where to forward data:

http://docs.splunk.com/Documentation/Splunk/latest/admin/Outputsconf

somesoni2
Revered Legend

You should've include the Summary index search head as part of your distributed deployment, so that it will directly save the summary index data onto Indexers.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...