The fill_summary_index.py script allows you to backfill the summary index for any time period that you like. It does this by running the saved searches which you have defined to populate your summary indexes, but only for the time periods you specify.
To use the script, follow the given procedure:
- Create your scheduled search, as detailed previously in the Populating summary indexes with saved searches section.
- Log in to the shell on your Splunk instance. If you are running a distributed environment, log in to the search head.
- Change directories to the Splunk bin directory:
cd $SPLUNK_HOME/bin
$SPLUNK_HOME is the root of your Splunk installation. The default installation directory is /opt/splunk ...