Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to schedule daily summary indexing with a search that uses the geostats command? Is there another approach?

$
0
0
My search is simple: sourcetype=log_data | iplocation c_ip | geostats latfield=lat longfield=lon count but I have a lot of data, about 100,000,000 logs a day, and the customer wants a monthly summary. A monthly search would be too slow. I'd like to be able to write a daily summary and schedule it, but there is no summary indexing for the geostats command. (**si**geostats ). Ideas on another way to approach this?

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>