collapse
The collapse
command is an internal, unsupported, experimental command. See
About internal commands.
Description
The collapse command condenses multifile results into as few files as the chunksize
option allows. This command runs automatically when you use outputlookup and outputcsv commands.
Syntax
... | collapse [chunksize=<num>] [force=<bool>]
Optional arguments
- chunksize
- Syntax: chunksize=<num>
- Description: Limits the number of resulting files.
- Default: 50000
- force
- Syntax: force=<bool>
- Description: If force=true and the results are entirely in memory, re-divide the results into appropriated chunked files.
- Default:
false
Examples
Example 1: Collapse results.
... | collapse
About internal commands | dump |
This documentation applies to the following versions of Splunk Cloud Platform™: 8.2.2112, 8.2.2201, 8.2.2202, 8.2.2203, 9.0.2205, 9.0.2208, 9.0.2209, 9.0.2303, 9.0.2305, 9.1.2308, 9.1.2312, 9.2.2403 (latest FedRAMP release), 9.2.2406
Feedback submitted, thanks!