Hi @Ash1 , as also @PickleRick said, copying logs from one index in another one you pay twice your license (if you want to maintain the same sourcetype), is this acceptable for you? Why do you want...
See more...
Hi @Ash1 , as also @PickleRick said, copying logs from one index in another one you pay twice your license (if you want to maintain the same sourcetype), is this acceptable for you? Why do you want to do this? if the reason is the access grants you could use 4 indexes for EP data and one for both EP and EM data, in this way you don't need to duplicate them. Anyway, there is one way to copy logs from an index to another and it isn't relevant if they come from 4 indexes and must be copied in one: 1) schedule a search and add at the end the collect command, something like this: index IN (app-ep-index1, app-ep-index2, app-ep-index3, app-ep-index4) <condition_of_the_log_to_be_copied>
| collect index=app-em-index sourcetype=ypur_sourcetype) this solution has three limits: you pay twice the license, there's a delay in the data availability in the app-em-index, yu have to schedule one search for each sourcetype you want to copy. My hint is to send common logs to one index and give grants to both the groups to this index. Ciao. Giuseppe