Splunk Search

Is It possible do two different searches and write the output data in another index?

italogf
Explorer

Is It possible do two different searches and write the output data in another index?

Tags (3)
0 Karma
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

Yes it is. You can collect the output of the search string and place it into another index.

<your_searches> | collect index=<your_index>

If you comment with your full search string we can help more.

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

Yes it is. You can collect the output of the search string and place it into another index.

<your_searches> | collect index=<your_index>

If you comment with your full search string we can help more.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...