I want to take one of my index and make faster, like this:
index=ltm
summary_index=ltm_summary
Thank you guys.
Note that a summary index is not magic. It's faster than a regular index because you've done something (like stats, etc) to distill the data, and reduce the overall number of rows. Simply copying one index to a summary index doesn't make it faster.
Not quite.
You will need two indexes. "ltm" and "ltm_summary".
To populate the summary index (quick and dirty): your_search | do_things | collect index=ltm_summary
To use the summary index: your_search index=ltm_summary | do_more_things
You will want to review this: http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Usesummaryindexing
Has this helped? Please mark accepted if it answered your question.