<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Collect Command in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Collect-Command/m-p/133431#M1360</link>
    <description>&lt;P&gt;some extra fields will be added to the orinal index. you are going to loose event structure, host will change to local splunk instance name. you can see by using a single event collect. Rather than using collect you could copy the buckets.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;A href="http://answers.splunk.com/answers/118518/is-it-possible-to-divide-an-index-to-two-indexes?page=1&amp;amp;focusedAnswerId=118536#118536" target="test_blank"&gt;http://answers.splunk.com/answers/118518/is-it-possible-to-divide-an-index-to-two-indexes?page=1&amp;amp;focusedAnswerId=118536#118536&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Apr 2014 04:59:41 GMT</pubDate>
    <dc:creator>linu1988</dc:creator>
    <dc:date>2014-04-17T04:59:41Z</dc:date>
    <item>
      <title>Collect Command</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Collect-Command/m-p/133427#M1356</link>
      <description>&lt;P&gt;Is it possible to use collect command to collect data from one index and move it to another, where destiation index is not a summary index ?&lt;/P&gt;

&lt;P&gt;index=whatever host=whatever source=whatever whatever | collect index=foo&lt;/P&gt;

&lt;P&gt;Where foo is pre-configured index in indexes.conf.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 13:32:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Collect-Command/m-p/133427#M1356</guid>
      <dc:creator>ManishaAgrawal</dc:creator>
      <dc:date>2014-04-16T13:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Collect Command</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Collect-Command/m-p/133428#M1357</link>
      <description>&lt;P&gt;Sure. I don't think collect really cares where it gets dumped, just be aware that there will probably be some summary data within the dumped information.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 13:34:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Collect-Command/m-p/133428#M1357</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2014-04-16T13:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: Collect Command</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Collect-Command/m-p/133429#M1358</link>
      <description>&lt;P&gt;Thanks Alacercogitatus&lt;/P&gt;

&lt;P&gt;Could you please highlight what summary data would be indexed.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 13:39:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Collect-Command/m-p/133429#M1358</guid>
      <dc:creator>ManishaAgrawal</dc:creator>
      <dc:date>2014-04-16T13:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: Collect Command</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Collect-Command/m-p/133430#M1359</link>
      <description>&lt;P&gt;Thanks Alacercogitatus&lt;/P&gt;

&lt;P&gt;Could you please highlight what summary data would be indexed.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Apr 2014 13:40:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Collect-Command/m-p/133430#M1359</guid>
      <dc:creator>ManishaAgrawal</dc:creator>
      <dc:date>2014-04-16T13:40:08Z</dc:date>
    </item>
    <item>
      <title>Re: Collect Command</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Collect-Command/m-p/133431#M1360</link>
      <description>&lt;P&gt;some extra fields will be added to the orinal index. you are going to loose event structure, host will change to local splunk instance name. you can see by using a single event collect. Rather than using collect you could copy the buckets.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;&lt;A href="http://answers.splunk.com/answers/118518/is-it-possible-to-divide-an-index-to-two-indexes?page=1&amp;amp;focusedAnswerId=118536#118536" target="test_blank"&gt;http://answers.splunk.com/answers/118518/is-it-possible-to-divide-an-index-to-two-indexes?page=1&amp;amp;focusedAnswerId=118536#118536&lt;/A&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2014 04:59:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Collect-Command/m-p/133431#M1360</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-04-17T04:59:41Z</dc:date>
    </item>
  </channel>
</rss>

