Using fill_summary_index.py to backfill

The fill_summary_index.py script allows you to backfill the summary index for any time period that you like. It does this by running the saved searches which you have defined to populate your summary indexes, but only for the time periods you specify.

To use the script, follow the given procedure:

  1. Create your scheduled search, as detailed previously in the Populating summary indexes with saved searches section.
  2. Log in to the shell on your Splunk instance. If you are running a distributed environment, log in to the search head.
  3. Change directories to the Splunk bin directory:
cd $SPLUNK_HOME/bin  

$SPLUNK_HOME is the root of your Splunk installation. The default installation directory is /opt/splunk ...

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.