Splunk Search

Dump search result into new index

smileyge
Path Finder

Is it possible to execute a query that merges several indexes and stores the result in another index which is then provided to end users for reporting? Reason to do so is to be able to accelerate the specific combinations of indexes and not need to do dynamic lookups on heavily used data sets that require a lookup otherwise.

1 Solution

martin_mueller
SplunkTrust
SplunkTrust

martin_mueller
SplunkTrust
SplunkTrust

Sure, you're probably looking for summary indexing: http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Usesummaryindexing

martin_mueller
SplunkTrust
SplunkTrust

Both the query writing to and the query reading from are regular Splunk searches... so anything you can do in a Splunk search, you can do in one of those.

0 Karma

smileyge
Path Finder

Can I take in lookup values or LDAPFILTER queries to supplement the eventData using a summary Index?

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...