Getting Data In

Filtering the data to different indexes

vishaltaneja070
Motivator

Hello Guys,

I have Splunk instance which is receiving data from different instances like DEV, QA, UAT and PROD. For then we have separate index like DEV_app, QA_app, UAT_app and PROD_app and they are sharing same sourcetype i.e. app.

Now the issue is, I need to filter events coming in two indexes i.e. Need to seperate debug logs, and as they are sharing same sourcetype so i can't apply filter based on it, as DEV_app filter data need to do to, DEV_debug, QA_app to QA_debug like this.

Any one has some solution to it?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...

Build and Launch AI Agents from Your Splunk Workflows

Replay Tech Talk Build and Launch AI Agents from Your Splunk Workflows     We’ve all been there: juggling ...

index This | What kind of room has no doors?

IndexEducation Cover Art Banner Cisco.png August 2026 Edition  Hayyy Splunk Education Enthusiasts and the ...