Splunk Doc on collect command is a bit confusing:
source: http://docs.splunk.com/Documentation/Splunk/6.5.2/SearchReference/Collect#Moving_events_to_a_different_index
Moving events to a different index
You can use the collect command to move selected file content from one index to another index. Construct a search that returns the data you want to port, and pipe the results to the collect command. For example:
index=whatever host=whatever source=whatever whatever | collect index=foo
This search ports the data into the foo index. The sourcetype is changed to stash.
You can specify a sourcetype with the collect command. However, specifying a sourcetype counts against your license, as if you indexed the data again.
... View more