hello
I want to use this search index=maillog I transaction qid maxspan=1m maxpause=30s and put the result into a new index how to set it
thank you
Have a look at the collect
command:
http://docs.splunk.com/Documentation/Splunk/7.0.3/SearchReference/Collect