Is it possible to save data returned from a virtual index into another virtual index using the
collect command in Splunk?
Currently, if I set up a new Virtual Index to point to a blank area in HDFS with read/write permissions and use this as the target of a search with the collect statement such as
index=syslog date_hour=12 | collect index=collect_test, no data is written to the virtual index when I search just this virtual index.
The above works when using a physical index as the target of the collect command, but not when using a virtual index.