Knowledge Management

How to add events to an index like logevents but without using alert (using a search for instance)?

splunkreal
Motivator

Hello guys,

how to add events to an index like logevents but without using alert (using a search for instance)?

There is "collect" command but not sure it applies to non-summary indexes?

Thanks.

Splunk 6.5.2 clustered environment.

* If this helps, please upvote or accept solution 🙂 *
0 Karma
1 Solution

DalJeanis
Legend

Yes, you CAN use collect. Or you could set up your configuration to use CLONE_SOURCETYPE, depending on your use case.

Despite the name, asummary index does not necessarily have to contain only a summary style of data. Summary indexes provide a method to store pretty much any stuff you want. It can contain an entire copy of raw events, or even a copy of raw events with additional enrichment data added, making the detail events even bigger. If you need a different retention length for certain kinds of events, you CAN copy them to a summary index for that kind of treatment. Or you could use CLONE_SOURCETYPE.

There are lots of tools in the shed around here. If you tell us a little more about what you are trying to accomplish, then we can steer you through your options.

View solution in original post

DalJeanis
Legend

Yes, you CAN use collect. Or you could set up your configuration to use CLONE_SOURCETYPE, depending on your use case.

Despite the name, asummary index does not necessarily have to contain only a summary style of data. Summary indexes provide a method to store pretty much any stuff you want. It can contain an entire copy of raw events, or even a copy of raw events with additional enrichment data added, making the detail events even bigger. If you need a different retention length for certain kinds of events, you CAN copy them to a summary index for that kind of treatment. Or you could use CLONE_SOURCETYPE.

There are lots of tools in the shed around here. If you tell us a little more about what you are trying to accomplish, then we can steer you through your options.

adonio
Ultra Champion
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...