Splunk® Cloud Services

SPL2 Search Reference

thru command syntax details


The required syntax is in bold.

[mode = (append | replace)]

Required arguments

Syntax: <dataset>
Description: The name of the dataset to write the search results to.

Optional arguments

Syntax: mode=(append | replace)
Description: Specifies whether the search results are appended to the existing data in the dataset or replace the data in the dataset.
Default: append

See also

thru command
thru command overview
thru command usage
thru command examples
Last modified on 20 October, 2020
thru command overview   thru command usage

This documentation applies to the following versions of Splunk® Cloud Services: current

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters