Merriam Webster says, “collect: to get things from different places and bring them together”

THE ‘collect’ COMMAND

The ‘collect’  command is used to replicate data from one index into another.  The assumed usage, and original intent, of this command is to aggregate granular events into a summary index.  In fact, the documentation states that is its purpose in the Synopsis – “Put search results into a summary index.”  But that need not always be the case.  There are other uses for the ‘collect’ command, as well – result sets can be collected at either a granular or aggregate (summary) level.  And they may be retained in regular or summary indexes.

There are no licensing implications to duplicating the data in another index – after the original data is indexed, it is not counted again …

» Continue reading

ETL >> SplunkTL

"Splunk allows you to impose structure on any and all of your unstructured data!"
» Continue reading


"The Splunk Search Processing Language can be easier than SQL."
» Continue reading


"What buzzwords should I listen for to find a new Splunk opportunity?"
» Continue reading