place="that_place" rename ip AS src
In your rename command, there is no leading pipe or its typo ?
Anyways I think better to move dedup in outer search
... View more
This App is crap. If you have set of requirements then I can provide you queries which you schedule using splunk cron. Which will save good amount data ingestion
... View more
I hope your index list is fixed. You can create lookup with all the index names then append that into your search results. Further, join to find out empty indexes
... View more