I have a saved search in the default summary index and when I use the index=summary
in my search box, I cannot find the summary index? Not sure why?
Your Splunk role must have permissions to access the summary index.
Also, similar to @somesoni2 - is there any data in the summary index? How do you know your populating search is working?
So you have a scheduled search with alert action as summary indexing and it's sending data to index=summary? Is the search scheduled and have results? Did you select appropriate time-range while running your query to see the summary index data?