Summary indexes
A summary index is a designated Splunk index that stores the results of an ad hoc search piped to a collect command, or a scheduled report when you enable summary indexing for the report. Summary indexing lets you run fast searches over large datasets by spreading out the cost of a computationally expensive report over time. To achieve this, the search that populates the summary index runs on a frequent, recurring basis and extracts the specific data that you require. You can then run fast and efficient searches against this smaller subset of data in the summary index versus running the search across all the events in the source index. Because the footprint of a summary index is typically much smaller, you can keep the summarized ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access