I read the doc about the collect command. I understand how it works and what it does, but I wanted some practical example.
Because it is something that uses an index, so I'm afraid to touch it.
Thanks!
There was a session at 2013 .conf session that you can download from Splunk titled
Automating Operational Intelligence: Stats and Summary Indexes
It was by the brilliant and dapper Jesse Trucks. It might give you some really good ideas.
To find it, search in the .conf 2013 sessions for Jesse Trucks and download the Recording.
My use-cases for collect command is for doing One time summary indexing (save result of search result to an index) OR doing a backfill of a summary index if the backfill period is very small and continuous. This doesn't overwrite any existing data but use a test index to validate the result before using the actual index, to be sure.
Thank you!!!