Splunk Search

Why am I unable to find a summary index in search when using index=summary?

ashishlal82
Explorer

I have a saved search in the default summary index and when I use the index=summary in my search box, I cannot find the summary index? Not sure why?

Tags (2)
0 Karma

lguinn2
Legend

Your Splunk role must have permissions to access the summary index.
Also, similar to @somesoni2 - is there any data in the summary index? How do you know your populating search is working?

0 Karma

somesoni2
Revered Legend

So you have a scheduled search with alert action as summary indexing and it's sending data to index=summary? Is the search scheduled and have results? Did you select appropriate time-range while running your query to see the summary index data?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...