Splunk Enterprise

Using collect command: Why is some data missing?

welcome
Engager

I am using collect command to transfer data data from one index to another index 
The query is like index=A source=sourceA sourcetype:sourcetypeA host=hostA | collect index=B source=sourceA sourcetype:sourcetypeA host=hostA.
But some data is missing why

Labels (1)
Tags (1)
0 Karma

welcome
Engager

Can we have any other command to transfer one index data into another index 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Is it possible to re-ingest the data to the new index? Other than that, the collect command should do the trick.

 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

What sort of data is missing?

Have you tried using output_format=hec for the collect command 

https://docs.splunk.com/Documentation/Splunk/9.0.3/SearchReference/Collect#arg-options

 

0 Karma

welcome
Engager

I am getting events properly but the total number of A events not matching the B events 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

Can you find some information around the missing data - e.g. does it transfer a fixed number of events, but miss some others.

Are the time stamps the same and is the time window you are searching the same on both indexes?

 

 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...