Splunk Search

Where is Splunk creating my summary index?

a212830
Champion

Hi,
I have a customer who is scheduling a search that uses db query. He then wants to send the output of that search to a summary index. Since db connect runs from the search-head, will the summary index get created on the search-head? I'm trying to make all indexers are created on the indexers. (We are running Splunk 6.1.1)

0 Karma

bwooden
Splunk Employee
Splunk Employee

If your search head is setup as a forwarder, the summary index will be populated on the indexers. It sounds like this is what you want. That configuration (Forwarding Search Head data to Indexers) is considered a best practice. Additional information on why (& how to set that up) may be found here: http://docs.splunk.com/Documentation/Splunk/6.2.4/DistSearch/Forwardsearchheaddata.

Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...