<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alternate command for collect in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654191#M2435</link>
    <description>&lt;P&gt;Setting&amp;gt;Indexes&amp;gt;threathunting&lt;/P&gt;&lt;P&gt;It's enabled, deployed in the Global sharing permissions app. It also has home path for db.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bimatomsoc_0-1691925121141.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26777i9769704A427CB2B8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bimatomsoc_0-1691925121141.png" alt="bimatomsoc_0-1691925121141.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 13 Aug 2023 11:12:43 GMT</pubDate>
    <dc:creator>bimatomsoc</dc:creator>
    <dc:date>2023-08-13T11:12:43Z</dc:date>
    <item>
      <title>Is there an alternate command for collect?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/527135#M294</link>
      <description>&lt;P&gt;Hi ,&lt;BR /&gt;&lt;BR /&gt;Do we have any command in splunk which does similar functionality like "Collect " command.&lt;BR /&gt;Can someone suggest on this?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 17:03:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/527135#M294</guid>
      <dc:creator>knanaiah001</dc:creator>
      <dc:date>2023-08-14T17:03:18Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/527139#M296</link>
      <description>Can you describe your issue where you are needing this?</description>
      <pubDate>Thu, 29 Oct 2020 16:46:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/527139#M296</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-10-29T16:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654171#M2425</link>
      <description>&lt;P&gt;We cannot use "collect" command&lt;BR /&gt;Please see my example search:&lt;BR /&gt;&lt;BR /&gt;index="main"&lt;BR /&gt;|table host index tag&lt;BR /&gt;|collect index="custom_index"&lt;BR /&gt;&lt;BR /&gt;It didn't work. No results were collected in "custom_index"&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 08:41:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654171#M2425</guid>
      <dc:creator>bimatomsoc</dc:creator>
      <dc:date>2023-08-13T08:41:48Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654173#M2426</link>
      <description>&lt;P&gt;Do you have permissions to read the index? Do you have permissions to run the collect command? What search are you using to check whether events have been written?&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 09:18:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654173#M2426</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-13T09:18:51Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654179#M2427</link>
      <description>&lt;P&gt;We have a new index named "threathunting" and having permission to collect the results. We use splunk admin account.&lt;BR /&gt;How do we check that we have permission to run collect command?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 09:49:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654179#M2427</guid>
      <dc:creator>bimatomsoc</dc:creator>
      <dc:date>2023-08-13T09:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654181#M2428</link>
      <description>&lt;P class="lia-align-left"&gt;Does your original search return any results at all? (Without the collect part)&lt;/P&gt;&lt;P class="lia-align-left"&gt;It doesn't seem right or at least doesn't seem like good practice to have events in the main index.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 09:57:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654181#M2428</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-08-13T09:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654182#M2429</link>
      <description>&lt;P&gt;Yes, the original command without |collect is working fine and gets results.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;index="main"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;|table host index tag&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Till this command, it shows results as table.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 10:02:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654182#M2429</guid>
      <dc:creator>bimatomsoc</dc:creator>
      <dc:date>2023-08-13T10:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654183#M2430</link>
      <description>&lt;P&gt;What search are you using to get the results from the summary index?&lt;/P&gt;&lt;P&gt;What does the job inspector say about the search you use to collect the events? (It should say something about successfully writing the results to stash.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 10:10:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654183#M2430</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-13T10:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654184#M2431</link>
      <description>&lt;P&gt;Yes, the original command without |collect is working fine and gets results.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;index="main"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;|table host index tag&lt;BR /&gt;&lt;/SPAN&gt;|head 10&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Till this command, it shows the results with table. When I put the collect command,&amp;nbsp;the search run has no error, still showing the head 10 results.&lt;/P&gt;&lt;P&gt;|collect index="threathunting"&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;But, the results are not collected in the "threathunting" index.&lt;BR /&gt;&lt;BR /&gt;I already created a empty "threathunting" index, get permission and accessible index.&lt;BR /&gt;&lt;BR /&gt;So, the head 10 results should be collected in "threathunting" index. Yet, it can't.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 10:22:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654184#M2431</guid>
      <dc:creator>bimatomsoc</dc:creator>
      <dc:date>2023-08-13T10:22:48Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654186#M2432</link>
      <description>&lt;P&gt;After you run the search with the collect command, even if there is no error, there should still be a message in the job. What messages do you get when you click on the job button&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ITWhisperer_0-1691922661949.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26776i3B86975ABE85903B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ITWhisperer_0-1691922661949.png" alt="ITWhisperer_0-1691922661949.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 10:31:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654186#M2432</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-13T10:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654187#M2433</link>
      <description>&lt;P&gt;Successfully wrote file to '/opt/splunk/var/spool/splunk/b90a7184a4568807_events.stash_new'.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 10:36:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654187#M2433</guid>
      <dc:creator>bimatomsoc</dc:creator>
      <dc:date>2023-08-13T10:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654188#M2434</link>
      <description>&lt;P&gt;If&amp;nbsp; you go to settings -&amp;gt; indexes, what does it say about your index?&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 10:46:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654188#M2434</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-13T10:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654191#M2435</link>
      <description>&lt;P&gt;Setting&amp;gt;Indexes&amp;gt;threathunting&lt;/P&gt;&lt;P&gt;It's enabled, deployed in the Global sharing permissions app. It also has home path for db.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bimatomsoc_0-1691925121141.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26777i9769704A427CB2B8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bimatomsoc_0-1691925121141.png" alt="bimatomsoc_0-1691925121141.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 11:12:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654191#M2435</guid>
      <dc:creator>bimatomsoc</dc:creator>
      <dc:date>2023-08-13T11:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654193#M2436</link>
      <description>&lt;P&gt;Looks like no events in the index - do you have any errors in the splunkd.log?&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 12:00:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654193#M2436</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-13T12:00:52Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654213#M2437</link>
      <description>&lt;P&gt;Is this a clustered environment? Do you have access to the file system and is the stash file still there?&lt;/P&gt;&lt;P&gt;Check the _internal index for any evidence of that stash file&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 02:59:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654213#M2437</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-08-14T02:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654262#M2438</link>
      <description>&lt;P&gt;Yes, it was found in _internal index.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bimatomsoc_1-1692009249422.png" style="width: 866px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26785iFC24300CEFE49D4C/image-dimensions/866x92?v=v2" width="866" height="92" role="button" title="bimatomsoc_1-1692009249422.png" alt="bimatomsoc_1-1692009249422.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also, this is a cluster environment. We have access to file system but there is no *_events.stash_new file under the /opt/splunk/var/spool/splunk/ directory.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 10:38:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654262#M2438</guid>
      <dc:creator>bimatomsoc</dc:creator>
      <dc:date>2023-08-14T10:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654263#M2439</link>
      <description>&lt;P&gt;Yes, "threathunting" index is empty and created to collect search results.&amp;nbsp;&lt;BR /&gt;No error in splunkd.log&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 10:40:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654263#M2439</guid>
      <dc:creator>bimatomsoc</dc:creator>
      <dc:date>2023-08-14T10:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: Alternate command for collect</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654316#M2440</link>
      <description>&lt;P&gt;If this is clustered and your 'index' is showing no events, then I suspect there may be something going on with one index being on the search head and one on the indexer and you have an issue with data being ingested to one index rather than the other.&lt;/P&gt;&lt;P&gt;That sounds like an admin issue and I am not sure how to verify that.&lt;/P&gt;&lt;P&gt;Did you create the threathunting index through the UI on the search head - if so, that means the index is on the SH, not the indexers. Creating indexes on the indexers is not done through the UI, it needs to be set up in the conf files for the indexers.&lt;/P&gt;&lt;P&gt;If this is the case, I suspect the data is being "ingested" to a threathunting index that does not exist on the indexer, as you created it on the search head.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 02:00:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-there-an-alternate-command-for-collect/m-p/654316#M2440</guid>
      <dc:creator>bowesmana</dc:creator>
      <dc:date>2023-08-15T02:00:42Z</dc:date>
    </item>
  </channel>
</rss>

