Splunk® Cloud Services

SPL2 Search Reference

into command syntax details


The required syntax is in bold.

[ mode=append | replace ]

Required arguments

Syntax: <dataset>
Description: The name of a lookup or splv1sink dataset that you have access to. This can be a dataset that you created or a dataset that you are authorized to use.

Optional arguments

Syntax: mode=( append | replace )
Description: Specifies whether to append results to or replace results in the specified dataset. The mode only applies to lookups. The mode is not used with datasets where the kind of dataset is spl1sink.
Default: append

See also

into command
into command overview
into command usage
into command examples
Related information
Dataset kinds in the SPL2 Search Manual.
Last modified on 20 August, 2021
into command overview   into command usage

This documentation applies to the following versions of Splunk® Cloud Services: current

Was this topic useful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters