Can summaryindexes, aka stash files, be stored somewhere other than $SPLUNK_HOME/var/spool/splunk/_.stash? Specifically, can the $SPLUNK_HOME part be changed?
Disk space is the issue. I have a...
I want to be able to use the search GUI to create summaryindex searches, but i want the actual resulting summaryindex to live on my distributed indexers. how can i accomplish this?
...hat I would like to do is configure the saved searches that write to a summaryindex on the search head and write summary data to summaryindexes on the indexers where i search.
Is this possible/the r...
Hi
I need to run a series of summary generating searches, one followed by another.
e.g.
summary search1 generates summary data from raw, and stores the summary data in summaryindex1
summary...
...ome searches and store the results by enabling summaryindex at rpp_pe_summary_idx_dmc. Question here is we need to update the indexes.conf to meet below requirements.
Hot&Warm buckets will h...
...o the end of a well used indexes.conf file and is successfully deployed to the indexers:
[throwaway]
homePath = volume:primary/throwaway
coldPath = volume:primary/throwaway/colddb
t...
...olutions to help me display the service_name field in the summaryindex, I would greatly appreciate it. Any troubleshooting steps, configuration changes, or alternative approaches you can recommend would be o...
Hi Team, I was comparing the SummaryIndex transaction time with the live Splunk server transaction time. I see all transactions collected in 15min bucket keep the same time and override the a...