I want to know how to replace a value inside in index permanently. I know I can use replace to replace it during search time but want to modify the actual value inside the index permanently.
I need this as equipment hostnames may change but I want to keep historical data for that host under the same indexed value.
asked 21 Mar '12, 10:10
Splunk is unlike a relational-database in that once a value is written to the index, it cannot be removed/replaced surgically.
Thus, for historical data, you will need to reindex the data in question and then use a SED command to do the replacement:
Unless you reindex your old data, the replacement will be effective only for data going forward.