<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrating from SumoLogic, Needing to import log data in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Migrating-from-SumoLogic-How-to-import-log-data/m-p/607518#M1688</link>
    <description>&lt;P&gt;What do you mean by "&lt;SPAN&gt;Im unable to see all the indexes"?&amp;nbsp; Is it just a matter of your role not having access to the indexes?&amp;nbsp; If so, then all you can do is ask your Splunk admin for access or have him/her do the import.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk should be able to maintain the original host.&amp;nbsp; Is the host name in the CSV file?&amp;nbsp; If so, then props and transforms can be used to preserve the host name.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In both cases, it may help if you gave us some more information about how you are doing the import.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jul 2022 12:20:07 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2022-07-29T12:20:07Z</dc:date>
    <item>
      <title>Migrating from SumoLogic: How to import log data?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Migrating-from-SumoLogic-How-to-import-log-data/m-p/607415#M1687</link>
      <description>&lt;P&gt;So here at work we have been using Sumo for a couple years now but are moving to Splunk.&amp;nbsp; I have been looking for ways of moving the log/event data. Now I know I can export a search from Sumo into a CSV then import it.&amp;nbsp; However Im unable to see all the indexes to import the data to on the Splunk side. There's also the issue of the host change. Maybe Splunk is just unable to maintain the original host: values from the imported data, but if that's true I'd need to validate it for the boss.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So anyway, Im asking here for advice on the proper/accepted/best way to accomplish moving historical data from Sumo into Splunk.&amp;nbsp; And what the stipulations are on which indexes show up as destinations.&amp;nbsp; And lastly.. why can't splunk respect the host values of the imported records?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!!&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 15:21:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Migrating-from-SumoLogic-How-to-import-log-data/m-p/607415#M1687</guid>
      <dc:creator>Skeer-Jamf</dc:creator>
      <dc:date>2022-07-29T15:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from SumoLogic, Needing to import log data</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Migrating-from-SumoLogic-How-to-import-log-data/m-p/607518#M1688</link>
      <description>&lt;P&gt;What do you mean by "&lt;SPAN&gt;Im unable to see all the indexes"?&amp;nbsp; Is it just a matter of your role not having access to the indexes?&amp;nbsp; If so, then all you can do is ask your Splunk admin for access or have him/her do the import.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Splunk should be able to maintain the original host.&amp;nbsp; Is the host name in the CSV file?&amp;nbsp; If so, then props and transforms can be used to preserve the host name.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In both cases, it may help if you gave us some more information about how you are doing the import.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 12:20:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Migrating-from-SumoLogic-How-to-import-log-data/m-p/607518#M1688</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-07-29T12:20:07Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from SumoLogic, Needing to import log data</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Migrating-from-SumoLogic-How-to-import-log-data/m-p/607525#M1689</link>
      <description>&lt;P&gt;Ok so I login to Splunk, click on the + sign and choose to upload a local file.&amp;nbsp; Next is setting the source type.. by default the source type is 'csv'. I see individual entries.. they look correct in the right hand section so I'm assuming I'd leave that as 'csv'.&amp;nbsp; So next is setting the Input Settings/host field value. It's here where the default value is a weird string+domain.splunkcloud.com.&amp;nbsp; So that's a confusing part, but below that is the Index where to import this data to.&amp;nbsp; It's here that the drop down is only a SUPER small subset of the available indexes that I have access to/own.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2022 13:04:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Migrating-from-SumoLogic-How-to-import-log-data/m-p/607525#M1689</guid>
      <dc:creator>Skeer-Jamf</dc:creator>
      <dc:date>2022-07-29T13:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from SumoLogic, Needing to import log data</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Migrating-from-SumoLogic-How-to-import-log-data/m-p/607681#M1690</link>
      <description>&lt;P&gt;The "weird string" is the host name for your search head.&amp;nbsp; You can let that default because you'll need to override it, anyway.&lt;/P&gt;&lt;P&gt;You'll need to create an app with a transforms.conf file that sets the host name to a value in the data.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Overridedefaulthostassignments" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Overridedefaulthostassignments&lt;/A&gt; for a good description of that.&amp;nbsp; Use a heavy forwarder as described in the doc or build an app and upload it Splunk.com.&amp;nbsp; Either way, I recommend putting the .conf files in an app directory rather than in etc/system/local.&lt;/P&gt;&lt;P&gt;When you've done this, you'll have a custom sourcetype and should use that name rather than the built-in csv sourcetype.&lt;/P&gt;&lt;P&gt;I don't know why you're not seeing all of the index names.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2022 21:08:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Migrating-from-SumoLogic-How-to-import-log-data/m-p/607681#M1690</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-07-31T21:08:05Z</dc:date>
    </item>
  </channel>
</rss>

