Summary index searches

You can use established summary indexes for just about any saved search or report. Using Splunk Web, summary indexing is an alert option for scheduled reports. To leverage a summary index for a saved report:

  1. Navigate to Settings > Searches, Reports, and Alerts
  2. Select the name of your report
  3. Under Schedule and alert, select Schedule
  4. Schedule the report (Splunk.com states that "searches that populate summary indexes should run on a fairly frequent basis in order to create statistically accurate final reports")
  5. Under Alert, set Condition to Always
  1. Set Alert mode to Once per search
  2. Under summary indexing, select Enable
  3. Select the name of the summary index that the report populates from the Select the summary index 

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.