Splunk Search

How to schedule daily summary indexing with a search that uses the geostats command? Is there another approach?

cheinlein
Engager

My search is simple:

sourcetype=log_data | iplocation c_ip | geostats latfield=lat longfield=lon count

but I have a lot of data, about 100,000,000 logs a day, and the customer wants a monthly summary. A monthly search would be too slow. I'd like to be able to write a daily summary and schedule it, but there is no summary indexing for the geostats command. (sigeostats ). Ideas on another way to approach this?

0 Karma

knielsen
Contributor

You don't need the si commands at all to populate a summary index. Your search works fine as a daily search for that. Well, it depends on what you do with the data later on. I have about 200 summary indexes in place, I never even tried the si commands, they are all built by searches using stats.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...