Hey Everybody,
We started to work with multiple summary indexes. We are filling them up with scheduled searches and what are end with the "collect" command and this cause a lot of inconvenience.
Now we are thinking about that we would like to use alert action for the send-to-the-summary-index step, like when we write out data to a lookup with the "Output results to lookup" alert action.
Do you know any plug and play solution / downloadable alert action what we can use to improve our Splunk infra?
Thank you in advance!