Hi there!
Is there a search command that will allow me to look up results from a "saved result"? I'm looking for ways I could speed up my populating search. My populating search is taking too l...
...ith the results of a search, but in this case the data summary is actually a special summaryindex that is built and stored on the search head. Usesummaryindexingforincreased reporting efficiency s...
...m a bit confued when to use the collect command.
I have configured the search (report) with the summaryindex, but nothing happened...
What am I doing wrong?
I am trying to make a summaryindexfor data in April 2014.
Using the current default search and joins, and to query more than 25 GB of data takes more than 35 seconds of time.
I want to use a...
Hi,
I have a search that will fetch about 5 GB of application logs. In order not to put load on the Splunk instance and slow search output, i am planning to use "SummaryIndexing" using the new S...
...o i want to usesummaryindexfor improving the performance.
As summaryindex run's fast searches, My requirement is, i want to use the regular indexfor capturing today's data and for last 6 d...
...f i use collect - it doesn't seem to do exactly what i want. i see collect saves the data, but it is in the original form - less any renames, evals, etc; ignoring the fields statement which outputs o...
Hi Splunkers,
I am pretty new to the concept of Summaryindexing, would like some more detailed explanation with examples of why Summaryindexing is used. My broad understanding is that Summaryindexing...