Note: ensure that your relevant sourcetype (eg. syslog) is searchable in an index that can be searched by default when no index is specified.
Note: wait ~2 hours for the scheduled searches to start populating the summary_postfix index, and then view the included dashboards :)
Splunk includes the fill_summary_index.py script to backfill gaps in summary index collection by running the saved searches that populate the relevant summary index as they would have been executed at their regularly scheduled times for a given time range. In other words, even though your new summary_postfix index only started collecting data for the last hour, if necessary you can use fill_summary_index.py to fill the summary index with data from the past month.
Copyright (c) 2014 Luke Harris. All Rights Reserved.
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.