We have a summary search that runs every hour. I have read about the fill_summary_index.py
What i want to know is how do I fix data from several weeks ago. Things changed a few weeks ago and I need to adjust the summary search. Going forward things are good but how can I run the fill_summary_index.py and have it replace the data that is there?
I feel like with the dedup setting it would either skip or add into what I have. How do I replace for a time period.. or can I?
Thanks.
I generally delete the corrupted/incomplete data from summary index and then backfill.
I generally delete the corrupted/incomplete data from summary index and then backfill.
How do you delete the corrupt/incomplete data?
We run the delete command to delete (technically it just makes the data unsearchable) the required data. We run a search with appropriate data-source (index/sourcetype/source/host) and time range, check if the search is returning the data that you want to delete, and then add "| delete " command at the end to delete/make-unsearchable the same. This link should give you more details on the delete command.
Thanks. If you post in the answers I will mark this as answered.
We do the same.