If you install the Splunk App for Unix and Linux in a distributed environment and have configured the search heads in that environment to send data to the indexers, you might need to deploy the indexes.conf file that comes with the Splunk Supporting Add-on for Unix and Linux component (SA-nix/default/indexes.conf) onto your indexers to ensure that the unix_summary summary index is available. Failure to do so might cause issues with alerts for the app, as alerts use this special index.
... View more