Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

collect index="based on values"

$
0
0
Hi everybody, is it possible to create several summary index within one search? Example: "**Index A**" has a **field** "**OS**" with **values** "**Windows**", "**Linux**"... Is there a way to tell splunk to loop something like: `index=A | collect index="OS"` (where OS is the field-value) So that each result based on field OS will be stored in (allready created) index "Windows", "Linux", .... Many thanks in advance.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>