Knowledge Management

Schedule automatic summary backfill?

the_wolverine
Champion

I'd like to have summary backfill run on a scheduled basis to fill in the gaps automatically. I'd probably run this during non-peak hours to reduce any impact on the servers.

How can this be done?

inventsekar
SplunkTrust
SplunkTrust

http://docs.splunk.com/Documentation/Splunk/6.4.2/Knowledge/Managesummaryindexgapsandoverlaps
Use the backfill script to add other data or fill summary index gaps
The fill_summary_index.py script backfills gaps in summary index collection by
running the saved searches that populate the summary index as they would have
been executed at their regularly scheduled times for a given time range.

check this one as well.. FYI - This document refers to 3.x versions of Splunk.
http://wiki.splunk.com/Community:Summary_Indexing_Back_Fill

0 Karma

pradeepkumarg
Influencer

Did you get around with this?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...