I know you can setup multiple indexes for different types of data, but can you search against both in the same search string?
Ex. I have syslog data being indexed in MAIN. I have a second set of data, Oracle logs that I would like to place in a seperate Index....call it Oracle. Can I search across both indexes at the same time so I can correlate system errors with the Oracle errors?
I was told last Fall that this would be something we could do in the future when Splunk rebuilt their search engine. I am not sure if we now have that ability.
When I test this functionality(index=main AND index=oracle), I get an error stating "index specified multiple times, using only 'main'" This would appear to be something we can not do yet. I would like to understand if/when we can expect this.
Regards.