Knowledge Management

Adding fields to already "summary-indexed" data

sranga
Path Finder

Hi

I have some summary-indexed data over the last couple of months. I was wondering if its possible to add another field to this data. Is it possible to modify the underlying query to add this new field and get past data "fixed"?

For example, if I have the following query:
index=blah type=a | sitimechart field1

Could I modify this to be:
index=blah type=a | sitimechart field1 by field2

Thanks for your help.

Ranga

Tags (1)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

No it is not possible. Like all Splunk data, you basically can't modify it once it's been indexed.

You can however delete the old data and use the backfill script to re-generate the new data.

This is equivalent to what you're asking for anyway. There is no advantage to having the old summary data in your example. Your new summary would have to be regenerated from the original data, as it is impossible to construct (or "modify") "sitimechart field1 by field2" from "sitimechart field1" without simply regenerating from original.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

No it is not possible. Like all Splunk data, you basically can't modify it once it's been indexed.

You can however delete the old data and use the backfill script to re-generate the new data.

This is equivalent to what you're asking for anyway. There is no advantage to having the old summary data in your example. Your new summary would have to be regenerated from the original data, as it is impossible to construct (or "modify") "sitimechart field1 by field2" from "sitimechart field1" without simply regenerating from original.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...