Splunk Search

Dump search result into new index

smileyge
Path Finder

Is it possible to execute a query that merges several indexes and stores the result in another index which is then provided to end users for reporting? Reason to do so is to be able to accelerate the specific combinations of indexes and not need to do dynamic lookups on heavily used data sets that require a lookup otherwise.

1 Solution

martin_mueller
SplunkTrust
SplunkTrust

martin_mueller
SplunkTrust
SplunkTrust

Sure, you're probably looking for summary indexing: http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Usesummaryindexing

martin_mueller
SplunkTrust
SplunkTrust

Both the query writing to and the query reading from are regular Splunk searches... so anything you can do in a Splunk search, you can do in one of those.

0 Karma

smileyge
Path Finder

Can I take in lookup values or LDAPFILTER queries to supplement the eventData using a summary Index?

0 Karma
Get Updates on the Splunk Community!

Announcing the Expansion of the Splunk Academic Alliance Program

The Splunk Community is more than just an online forum — it’s a network of passionate users, administrators, ...

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...