Splunk Search

Summary Indexing and Send data back to Indexers

nikhilmehra79
Path Finder

Hi,

I have build a dedicated Search head for running scheduled search and get summary indexing data, now i think it is recommended to send the summary indexed data back to indexers.How do we do this?

I have build a new index of 50 MB on this dedicated search head called si_summary. This is getting populated on this search head , but it never created same si_summary on my 2 indexers automatically.
So i manually created si_summary on 2 indexers but they still not populated with any data...any idea i am doing anything wrong. I am assuming job of summary indexer search head is to save summary data but that should not be stored on search head rather should be passed to indexer correct?

0 Karma
1 Solution

sbrant_splunk
Splunk Employee
Splunk Employee

You will need to have an outputs.conf on your search head, to let it know where to forward data:

http://docs.splunk.com/Documentation/Splunk/latest/admin/Outputsconf

View solution in original post

sbrant_splunk
Splunk Employee
Splunk Employee

You will need to have an outputs.conf on your search head, to let it know where to forward data:

http://docs.splunk.com/Documentation/Splunk/latest/admin/Outputsconf

somesoni2
Revered Legend

You should've include the Summary index search head as part of your distributed deployment, so that it will directly save the summary index data onto Indexers.

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...