Knowledge Management

Adding fields to already "summary-indexed" data

sranga
Path Finder

Hi

I have some summary-indexed data over the last couple of months. I was wondering if its possible to add another field to this data. Is it possible to modify the underlying query to add this new field and get past data "fixed"?

For example, if I have the following query:
index=blah type=a | sitimechart field1

Could I modify this to be:
index=blah type=a | sitimechart field1 by field2

Thanks for your help.

Ranga

Tags (1)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

No it is not possible. Like all Splunk data, you basically can't modify it once it's been indexed.

You can however delete the old data and use the backfill script to re-generate the new data.

This is equivalent to what you're asking for anyway. There is no advantage to having the old summary data in your example. Your new summary would have to be regenerated from the original data, as it is impossible to construct (or "modify") "sitimechart field1 by field2" from "sitimechart field1" without simply regenerating from original.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

No it is not possible. Like all Splunk data, you basically can't modify it once it's been indexed.

You can however delete the old data and use the backfill script to re-generate the new data.

This is equivalent to what you're asking for anyway. There is no advantage to having the old summary data in your example. Your new summary would have to be regenerated from the original data, as it is impossible to construct (or "modify") "sitimechart field1 by field2" from "sitimechart field1" without simply regenerating from original.

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...