Splunk Search

summary Index

VijaySrrie
Builder

Hi,

how will summary index actually work in relation to 'time based searches'
maybe the summary index could have no time value on each record?
 
We are replacing a lookup with a summary index.
 
we have 2000 entries in the lookup --> those entries will be pushed to summary index via a scheduled search
 
The lookup will be updated daily --> The updated data will go to summary Index
 
What will happen to old data that is already there in the summary Index?
 
Labels (3)
0 Karma
1 Solution

manjunathmeti
Champion

hi @VijaySrrie,

Summary index events do have timestamps.

if your saved search results contain a _time field then the timestamp will be set to this field values in the summary index. If _time is not there then timestamp is set to the CURRENT time(when data is parsed) in the summary index. 

Retention for the summary index is 5 years and the max data size is 500GB.

 

If this reply helps you, a like would be appreciated.

View solution in original post

manjunathmeti
Champion

hi @VijaySrrie,

Summary index events do have timestamps.

if your saved search results contain a _time field then the timestamp will be set to this field values in the summary index. If _time is not there then timestamp is set to the CURRENT time(when data is parsed) in the summary index. 

Retention for the summary index is 5 years and the max data size is 500GB.

 

If this reply helps you, a like would be appreciated.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...