Splunk Search

Summary Indexing and Send data back to Indexers

nikhilmehra79
Path Finder

Hi,

I have build a dedicated Search head for running scheduled search and get summary indexing data, now i think it is recommended to send the summary indexed data back to indexers.How do we do this?

I have build a new index of 50 MB on this dedicated search head called si_summary. This is getting populated on this search head , but it never created same si_summary on my 2 indexers automatically.
So i manually created si_summary on 2 indexers but they still not populated with any data...any idea i am doing anything wrong. I am assuming job of summary indexer search head is to save summary data but that should not be stored on search head rather should be passed to indexer correct?

0 Karma
1 Solution

sbrant_splunk
Splunk Employee
Splunk Employee

You will need to have an outputs.conf on your search head, to let it know where to forward data:

http://docs.splunk.com/Documentation/Splunk/latest/admin/Outputsconf

View solution in original post

sbrant_splunk
Splunk Employee
Splunk Employee

You will need to have an outputs.conf on your search head, to let it know where to forward data:

http://docs.splunk.com/Documentation/Splunk/latest/admin/Outputsconf

somesoni2
Revered Legend

You should've include the Summary index search head as part of your distributed deployment, so that it will directly save the summary index data onto Indexers.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...