Creating a summary index

To create an index, navigate to Settings | Indexes | New Index:

Note: The New Index page has changed a bit in version 7.0 but for now, let's simply give our new index a name and accept the default values.

We will discuss these settings under the indexes.conf section in Chapter 11, Configuring Splunk. I like to put the word summary at the beginning of any summary index, but the name does not matter. I would suggest you follow some naming convention that makes sense to you.

Now that we have an index to store events in, let's do something with it.

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.