Splunk Knowledge Object: Detail discussion on Summary Index

preview_player
Показать описание
In this video I have discussed about Summary Index implementation in splunk.
The below topics has been covered,

1. Why We need Summary Index?
2. How Summary index works?
3. Different use cases of Summary index.
4. How to create, populate and use summary index.
5. Summary index related commands sitop, sistats, addinfo, collect, overlap.
6. How to fill summary index gap.

Code and data used in this tutorial can be downloaded from the below repo:
Рекомендации по теме
Комментарии
Автор

Which ever video I see of yours find some thing new which never used in practical.... Thank you for the videos

vikashperiwal
Автор

Thanks for taking the time to walk us step-by-step how to implement this. I have attempted to do this as well and I'm running into an issue. It appears that after I create the report and I currently have it configured to run every hour, however ; the results for the first run are the only ones populating to the summary index. Subsequent reports are not populating the summary index and I think this is part of the reason, I'm not seeing my dashboard extract the right information. Any ideas why this might be happening? Thanks in advance.

LuisMartinez-kddn
Автор

Thank you for sharing this educational video. I created a saved search as report with summary index enabled. This scheduled search is to collect the data for the past 30 days with a frequency of 1 hour.When I open the link from the email generated, I get this response in splunk
"There are no results because the first scheduled run of the report has not completed." The query I used was:
sourcetype="pcf:Log" AND cf_space_name=perf AND cf_org_name=* | timechart span=1h dc(span_id) by cf_org_name usenull=f useother=f limit=10

joachimroshan
Автор

Thanks for explanation, no doubt you are the best even other than Splunk documents...only bad is i Observed all the scenarios surrounding your TMDB app....other than that you are awesome...but EOD your great teacher....

raovrmsf
Автор

Awesome video - I am happy that there is you who explains splunk - thank you and please keep going :-)

raggadaz
Автор

Actually i was searching for Summary index documents in google. But finally you have showed an hands on again. Great sir!!. I'm really happy now. I also kindly request you to create videos for Custom visualization creation!!

manigandanumapathy
Автор

Thank you so much Sir !!! Very detailed Explanation.
How can we add data Through con files(Instead of manual upload) - Is it possible to put a video for this one.

Sugreev
Автор

Great video! Do you have experience with metric indexes on how to send metrics and run searches off the metric index for increased performance?

phamryder
Автор

Hi Sir, while planning to implement summary indexing for our project, I came across few doubts.

1. Summary index can be applied in clustering environment?

2. If yes, where I should create index “tmdb_summary”? Create index in cluster master and push the bundle to indexers?

3. Do we need to do anything with search heads apart from creating scheduled search?

My questions might be wrong but seeking your inputs😊

manigandanumapathy
Автор

Nice video thank you very much, I would like to see a video on how to do a field extraction on summary

richardkouadio
Автор

Do you have any complete course on splunk? On udemy, or any other learning plataform? I mean any course that will cover everything till splunk archtect....

vinigreen
Автор

Do we need to use addinfo command also or we can direct push with collect cmd only?

divyasetia
Автор

Great Video!! Try to make a video on Splunk data storage too.

nilendrasingh
Автор

Sir pls try to create a video on report acceleration too

divyasetia
Автор

Joined today. I should have joined a long time ago.

Bangouaman
Автор

Sir thanks for Splunk knowledge.... could you please help me sir how to show license utilisation by index.

NSK
Автор

Hi Sir, I have a summary index that will be triggered by a summary search through schuduler....Is there a way to find out how many times that index triggered for a day...any internal field that tells the count for one execution...
Any suggestions would be really helpful

Sugreev
Автор

Sir, This is developing side are administration side

ravindraatla
Автор

Kindly do a video on PREDICT function.

raneeshkamar
Автор

Hi, using summary index can we search the data for 4 months in other index which data retention policy is only one month?

vikkyc