Getting Data In

Create a new sourcetype on the fly

asarolkar
Builder

I have a subsearch like this:

sourcetype="syslog" SERIAL=* | eval SERIAL_NUM=SERIAL | lookup FileLookup SERIAL_NUM

I want to take this and turn it into a new sourcetype.

Any ideas how to go about it ?

Tags (1)
0 Karma

Ayn
Legend

sourcetype for a log event is set at index-time, and as such you cannot change it afterwards.

Ayn
Legend

Not CREATE it on the fly, but you can certainly write the results of a search to another index. Check out the docs on summary indexing: http://docs.splunk.com/Documentation/Splunk/4.3.1/Knowledge/Usesummaryindexing

You'll likely want to make use of the collect command: http://docs.splunk.com/Documentation/Splunk/latest/searchreference/collect

0 Karma

asarolkar
Builder

can I create a new index then which has the results of this search ?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...