I have different log files .I want to combine these log files into a single file .Is this possible in splunk and if so how to do?
Can anyone give me some idea on it
Why would you do such a thing : Is your intention to export all the events as a single file ?
If you have indexed 2 files /path/to/file1 and /path/to/file2
why not searching on source=/path/to/file1 OR source=/path/to/file2
and have all the events displayed together.
No my intention is to combine the files together into single file before indexing
Index them into the same index and/or using the same sourcetype, then filter based on index and/or sourcetype and ignore the source altogether.
Can you suggest some documentation where i could see the process you said in detail.