<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to overwrite the indexer data. in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-overwrite-the-indexer-data/m-p/558516#M158654</link>
    <description>&lt;P&gt;Is there&amp;nbsp; any possibility to over write the index data ,&lt;/P&gt;&lt;P&gt;for example the data is indexing by the below query.&lt;BR /&gt;&lt;BR /&gt;| inputlookup&amp;nbsp; sample_Data.csv&amp;nbsp; | collect index= Collected_data&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;if i indexing the some other data to the same index ,&lt;BR /&gt;in this scenario the old data in the index should be over write by the new data , if it is possible ,&amp;nbsp; can you please explain how to do it.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;| inputlookup&amp;nbsp; sample_Data2.csv&amp;nbsp; | collect index= Collected_data&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 07 Jul 2021 09:22:00 GMT</pubDate>
    <dc:creator>vinod743374</dc:creator>
    <dc:date>2021-07-07T09:22:00Z</dc:date>
    <item>
      <title>How to overwrite the indexer data.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-overwrite-the-indexer-data/m-p/558516#M158654</link>
      <description>&lt;P&gt;Is there&amp;nbsp; any possibility to over write the index data ,&lt;/P&gt;&lt;P&gt;for example the data is indexing by the below query.&lt;BR /&gt;&lt;BR /&gt;| inputlookup&amp;nbsp; sample_Data.csv&amp;nbsp; | collect index= Collected_data&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;if i indexing the some other data to the same index ,&lt;BR /&gt;in this scenario the old data in the index should be over write by the new data , if it is possible ,&amp;nbsp; can you please explain how to do it.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;| inputlookup&amp;nbsp; sample_Data2.csv&amp;nbsp; | collect index= Collected_data&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 09:22:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-overwrite-the-indexer-data/m-p/558516#M158654</guid>
      <dc:creator>vinod743374</dc:creator>
      <dc:date>2021-07-07T09:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to overwrite the indexer data.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-overwrite-the-indexer-data/m-p/558518#M158655</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234515"&gt;@vinod743374&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you cannot modify any Splunk indexed data.&lt;/P&gt;&lt;P&gt;If you want a list of events always updated, you have to put them in a lookup or a KV Store.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 09:55:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-overwrite-the-indexer-data/m-p/558518#M158655</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-07T09:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to overwrite the indexer data.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-overwrite-the-indexer-data/m-p/558526#M158657</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234515"&gt;@vinod743374&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;tell me how can help you more.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 11:00:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-overwrite-the-indexer-data/m-p/558526#M158657</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-07T11:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to overwrite the indexer data.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-overwrite-the-indexer-data/m-p/558527#M158658</link>
      <description>&lt;P&gt;can you help me with any other alternative solution for my application.&lt;BR /&gt;&lt;BR /&gt;is there any command or search query to delete the previous data (sample_data.csv) in index and&amp;nbsp; indexing only the latest data (sample_data2.csv).&lt;BR /&gt;&lt;BR /&gt;| inputlookup&amp;nbsp; sample_data2.csv | collect index= Collected_data.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 11:08:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-overwrite-the-indexer-data/m-p/558527#M158658</guid>
      <dc:creator>vinod743374</dc:creator>
      <dc:date>2021-07-07T11:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to overwrite the indexer data.</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-overwrite-the-indexer-data/m-p/558537#M158663</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234515"&gt;@vinod743374&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;you have to stop to think to Splunk as a DB!&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk indexed logs that are no longer editable until cleared!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;If you need an always up-to-date situation of your data, you can create a search from your indexed data and save the results in a lookup using the outputlookup command.&lt;/P&gt;&lt;P&gt;At this point you can modify the data in the lookup that it's editable: in other words you can modify the data in the lookup but not in the Splunk indexes where they remain unchanged.&lt;/P&gt;&lt;P&gt;You can make changes to the lookup data using the Lookup Editor App or a specific search or JavaScript.&lt;/P&gt;&lt;P&gt;With Lookup Editor App it's very easy modify data but not controlled and not so beautiful.&lt;/P&gt;&lt;P&gt;Instead, updating lookup in a dashboard (using a search or a JS) it's not a five-minute work that can be suggested with an answer, but it does take time and Splunk knowledge.&lt;/P&gt;&lt;P&gt;To give you a hint of the steps to make it, you need to:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;recall the lookup in a dashboard,&lt;/LI&gt;&lt;LI&gt;select a record to edit with an in-page drilldown,&lt;/LI&gt;&lt;LI&gt;add one or more inputs to insert the values to be put or modified in the fields of the selected record,&lt;/LI&gt;&lt;LI&gt;update the record in the lookup with the outputlookup command.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I'm sorry I can't help you more but it's not an immediate thing!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 12:20:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-overwrite-the-indexer-data/m-p/558537#M158663</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-07T12:20:28Z</dc:date>
    </item>
  </channel>
</rss>

