You can use established summary indexes for just about any saved search or report. Using Splunk Web, summary indexing is an alert option for scheduled reports. To leverage a summary index for a saved report:
- Navigate to Settings > Searches, Reports, and Alerts
- Select the name of your report
- Under Schedule and alert, select Schedule
- Schedule the report (Splunk.com states that "searches that populate summary indexes should run on a fairly frequent basis in order to create statistically accurate final reports")
- Under Alert, set Condition to Always
- Set Alert mode to Once per search
- Under summary indexing, select Enable
- Select the name of the summary index that the report populates from the Select the summary index