<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Results from Collect command not writing to index? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631412#M219302</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;I recently took over a project by someone who is no longer with my employer. He made several scheduled searches that write to an index, and it was working great. However last month out of nowhere it just stopped working. Supposedly no changes were made.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The other searches are working, it's just this one. The search runs just fine, gets the expected results, but the results aren't being exported to the index.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I actually found another post on here with someone who looked to have the same problem, but it wasn't successfully answered.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another post suggested that a forwarder might be a solution. Does that seem right? I'd rather avoid that solution as I don't want to be installing apps on this environment, but if necessary I will get the permission. Just want to make sure that's a probable solution before doing so.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Feb 2023 21:46:04 GMT</pubDate>
    <dc:creator>Aroot002</dc:creator>
    <dc:date>2023-02-17T21:46:04Z</dc:date>
    <item>
      <title>Results from Collect command not writing to index?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631412#M219302</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;I recently took over a project by someone who is no longer with my employer. He made several scheduled searches that write to an index, and it was working great. However last month out of nowhere it just stopped working. Supposedly no changes were made.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The other searches are working, it's just this one. The search runs just fine, gets the expected results, but the results aren't being exported to the index.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I actually found another post on here with someone who looked to have the same problem, but it wasn't successfully answered.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another post suggested that a forwarder might be a solution. Does that seem right? I'd rather avoid that solution as I don't want to be installing apps on this environment, but if necessary I will get the permission. Just want to make sure that's a probable solution before doing so.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 21:46:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631412#M219302</guid>
      <dc:creator>Aroot002</dc:creator>
      <dc:date>2023-02-17T21:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Results from Collect command not writing to index?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631429#M219307</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234001"&gt;@Aroot002&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I suppose that you manually checked the scheduled search, but you checked it in the same time windows of the scheduled search?, in other words, if you search must run at 01.00 and there'a a condition earliest=now, you cannot check it at a different time, so try it again using the same time frame of the scheduled search.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 18 Feb 2023 07:26:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631429#M219307</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-18T07:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: Results from Collect command not writing to index?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631607#M219365</link>
      <description>&lt;P&gt;My earliest is 45 days ago and my latest is the current hour, as it is a scheduled hourly search. Results look exactly as they should but are not being written to the index.&lt;/P&gt;&lt;P&gt;Even so, if I run the search manually shouldn't the results of that search be written to the index? That's not happening.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 16:27:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631607#M219365</guid>
      <dc:creator>Aroot002</dc:creator>
      <dc:date>2023-02-20T16:27:38Z</dc:date>
    </item>
    <item>
      <title>Re: Results from Collect command not writing to index?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631616#M219366</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234001"&gt;@Aroot002&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if the collect command is at the end of your scheduled search, also manually running it results are written in the summary index.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 17:11:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631616#M219366</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-20T17:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Results from Collect command not writing to index?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631624#M219367</link>
      <description>&lt;P&gt;Yes, the last line is&lt;/P&gt;&lt;P&gt;| collect index=indexname source=sourcename&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;But when I run simply&lt;/P&gt;&lt;P&gt;index=indexname&lt;/P&gt;&lt;P&gt;after running that search, those results don't show up. Everything was working fine until one day in January when it just stopped writting results to the index.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 18:49:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631624#M219367</guid>
      <dc:creator>Aroot002</dc:creator>
      <dc:date>2023-02-20T18:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: Results from Collect command not writing to index?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631635#M219374</link>
      <description>&lt;P&gt;Figured it out, needed to add an eval column with the current time to match with the live results&lt;/P&gt;</description>
      <pubDate>Mon, 20 Feb 2023 20:51:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631635#M219374</guid>
      <dc:creator>Aroot002</dc:creator>
      <dc:date>2023-02-20T20:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Results from Collect command not writing to index?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631665#M219385</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234001"&gt;@Aroot002&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2023 07:25:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/631665#M219385</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-02-21T07:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: Results from Collect command not writing to index?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/708467#M239588</link>
      <description>&lt;P&gt;Collect is very time sensitive and as&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;pointed out. My search and collect writing to index was working. I changed the _time=now() to use a now time 14 eval statements earlier in the search and it stopped writing to the index. After viewing this thread, I changed it back to these final three lines in search and now successfully writing the results to index every time:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;| eval now=now()
| eval _time=now

| collect index=index output_format=raw spool=true source=yourSource sourcetype=stash&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 10 Jan 2025 21:58:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Results-from-Collect-command-not-writing-to-index/m-p/708467#M239588</guid>
      <dc:creator>Seawheels51</dc:creator>
      <dc:date>2025-01-10T21:58:31Z</dc:date>
    </item>
  </channel>
</rss>

