Splunk Search

What is the earliest and latest for running a backfill script in realtime?

Dark_Ichigo
Builder

I want to run a backfill script to create a summary index, I want to do this in realtime!

I have tried using the rt but it doesnt seem to work as I have seen other questions about this only working under times.conf.

How can I run a backfill script in realtime, I would Like an example and not just what I need to put in the limits.conf

Thanks

0 Karma

daskuntal
Path Finder

Yes, you already answered your question. I believe what you are trying to do is exactly what a Summary Indexed search is supposed to do. Perform a scheduled search to populate the summary index. The problem with taht is, you will only start fillign up the index from the moment you created & started the running the Search.

What backfill script does is goes back in time & pre-fills the Summary Index with data from whoever many months you want to go back to.

Hope that clarifies your question.

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

It's not possible to create a summary index in real time.

0 Karma

Dark_Ichigo
Builder

I want to run a backfill script to populate my summary index, the backfill script runs everyday via a cron job.

Can this be done without a backfill script and just a scheduled saved search with summary indexing enabled?

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I don't think I understand what you mean by backfill, or what you expect backfill is supposed to do.

0 Karma

Dark_Ichigo
Builder

Then whats the point of running a Backfill if you can just schedule a saved to populate a summary index?

Whats the closest to running a summary index in realtime?

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...