Hello,
I am using a summary index to track a handful of our key metrics per day over time. I am using the summary index for the purposes of improving search response times of panels on some of our dashboards.
The data in the summary index contains daily averages and counts per customer for 8 of our KPI’s. The events are written across 8 different sources in our summary index. About 600k total events are being written to the summary index each day. Are there any performance/capacity repercussions to this? From what I understand the summary index has no data retention limitations. Is 600k events per day in the summary index acceptable? We are using Splunk Cloud.
Thanks,
Chris
summary index is just like any other index
its limited by the configurations you set in indexes.conf (also via ui)
retention, size and other parameters are set by you