Knowledge Management

Is it possible to saved data returned from a virtual index into another virtual index using the collect command?

aaron_harris
Engager

Is it possible to save data returned from a virtual index into another virtual index using the collect command in Splunk?

Currently, if I set up a new Virtual Index to point to a blank area in HDFS with read/write permissions and use this as the target of a search with the collect statement such as index=syslog date_hour=12 | collect index=collect_test, no data is written to the virtual index when I search just this virtual index.

The above works when using a physical index as the target of the collect command, but not when using a virtual index.

0 Karma
1 Solution

rdagan_splunk
Splunk Employee
Splunk Employee

Writing to HDFS using the Collect command and Virtual Indexing will not work. However, you can use the Collect command to write to a normal Splunk summary index and then use the Hadoop Connect App to Export the data back to HDFS.

View solution in original post

rdagan_splunk
Splunk Employee
Splunk Employee

Writing to HDFS using the Collect command and Virtual Indexing will not work. However, you can use the Collect command to write to a normal Splunk summary index and then use the Hadoop Connect App to Export the data back to HDFS.

Get Updates on the Splunk Community!

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...