Splunk Dev

How to remove events from each summary index and backfill using fill_summary_index.py for a particular time period?

manja054
Explorer

Hi,

I am new to summary indexes.

I have scenario to work with.

i have summary index searches for 1min, 5min,1hr,and a day. My 1min & 5min indexes have events from main index and 1 hr summary index is based on 5min summary index and for 1day its based on an hour summary index.

i want to remove events from each summary index mentioned above for the period of 4\5\2016 22:00 to 4\8\2016 14:43 and back fill the same using fill_summary_index.py. (My deployment server was down on that particular time)

Can anyone help me how can i achieve this without duplication of events please?

0 Karma

somesoni2
Revered Legend

Information on How to delete data
http://docs.splunk.com/Documentation/Splunk/6.4.3/Indexer/RemovedatafromSplunk#Delete_events_from_su...

How to backfill summary index
http://docs.splunk.com/Documentation/Splunk/6.4.3/Knowledge/Managesummaryindexgapsandoverlaps#Use_th...

Make sure that, in both steps, you're using same time range (The time range of backfill script should be in a way that it reloads deleted data.)

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...