I have created a query
index="xxx" source="xxxxxx"|dedup dn|sistats count
scheduled this hourly
I could not find any data with
index=summary search_name="my schedule report name"
could not understand what went wrong, can anybody please help
Thank you
AB
changed the value of
action.summary_index to 1 in savedsearches.conf and then restared SPLUNK
it is working now
changed the value of
action.summary_index to 1 in savedsearches.conf and then restared SPLUNK
it is working now
Can you share the contents of savedsearches.conf
that shows the full configuration for your summary indexing search?
Thank you... forgot completely about savedsearches.conf.... working now ...