Hi,
I need to index lists of machines or users that I get with and ldapsearch,
I output them to CSV to make lookup,
BUT there are some cases where I would want results to be indexed.
How can I achieve this?
Hello Edouard,
You may want to check the collect command :
http://docs.splunk.com/Documentation/Splunk/6.4.0/SearchReference/Collect
example :
myldapsearch | collect index=test
YOu can use summary indexing to index result of a search to an index. See this
http://docs.splunk.com/Documentation/Splunk/6.0.2/Knowledge/Usesummaryindexing
http://docs.splunk.com/Documentation/Splunk/6.4.0/SearchReference/Collect
Hello Edouard,
You may want to check the collect command :
http://docs.splunk.com/Documentation/Splunk/6.4.0/SearchReference/Collect
example :
myldapsearch | collect index=test
We are in a similar situation but need to run the LDAP search on a HF and have the results sent back to the indexers however, when we run the collect command, it seems to just store the stash file locally on the server rather than writing back to the indexers.
Anyway to work around this and force the write back to indexers?
looks perfect,
thanks Simon 🙂