Getting Data In

Filtering the data to different indexes

vishaltaneja070
Motivator

Hello Guys,

I have Splunk instance which is receiving data from different instances like DEV, QA, UAT and PROD. For then we have separate index like DEV_app, QA_app, UAT_app and PROD_app and they are sharing same sourcetype i.e. app.

Now the issue is, I need to filter events coming in two indexes i.e. Need to seperate debug logs, and as they are sharing same sourcetype so i can't apply filter based on it, as DEV_app filter data need to do to, DEV_debug, QA_app to QA_debug like this.

Any one has some solution to it?

0 Karma
Get Updates on the Splunk Community!

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...

Print, Leak, Repeat: UEBA Insider Threats You Can't Ignore

Are you ready to uncover the threats hiding in plain sight? Join us for "Print, Leak, Repeat: UEBA Insider ...

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...