Hi, Thank you for your suggestion. When I use a scheduled report, and see the recent search, Splunk appends "| summaryindex" at the end of the search, not "collect" command. So, I thought "collect" always refers to "manual" push versus "summary index" in a scheduled report. My understanding you have 2 scheduled reports. Is the following accurate? 1) roll forward existing data (from and to the same summary index - say index A) 2) push new data (from a different index to summary index - say from index X to index A) In my case, the data from DBXquery is always get re-write, so I only need the latest data, but I may use your method in the future. Thanks for this. Based on the link that you sent and the following post, it looks like I still need the CSV file. (See below it does inputlookup to CSV first, then outputlookup to KV) Is this correct? My goal is to avoid having CSV file since there's a limit in size https://community.splunk.com/t5/Getting-Data-In/How-to-transfer-existing-CSV-data-to-kvstore/m-p/144641 | inputlookup filename.csv | outputlookup lookup_name Thank you again.
... View more