Does anyone know how to register log event to another index by SPL.
I'm assuming the answers like registering recodes from lookup file to an index executing a SPL regularly.
If there any way like that, please give your answer.
@smart111 - By registering an event, do you mean, indexing an event to index?
If so, then you can try using `collect` command.
For example if you wish to ingest entries from lookup file to index, your search would look something like this:
| inputlookup <your-lookup> | collect index=<index> sourcetype=<source>
- if the lookup is large, just make sure this event indexing is subject to license consumption just like normal Splunk data ingestion.
https://docs.splunk.com/Documentation/Splunk/8.2.3/SearchReference/Collect
@smart111 - By registering an event, do you mean, indexing an event to index?
If so, then you can try using `collect` command.
For example if you wish to ingest entries from lookup file to index, your search would look something like this:
| inputlookup <your-lookup> | collect index=<index> sourcetype=<source>
- if the lookup is large, just make sure this event indexing is subject to license consumption just like normal Splunk data ingestion.
https://docs.splunk.com/Documentation/Splunk/8.2.3/SearchReference/Collect
Thank you @VatsalJagani
That's really big help to me.
I could see a slution for the problem.
I appreciate.