<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to merge multiple index into single index? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-merge-multiple-index-into-single-index/m-p/628779#M15245</link>
    <description>&lt;P&gt;Hi splunk god,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Have enquiry, i have an environment which heavyforwarder logs send to cluster indexer.&lt;BR /&gt;I need the below multi index merge into single index which is index_general.&lt;BR /&gt;Basically, when user search index_general and able to search all the logs contain in the three index.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;1)Is this configuration feasible?&lt;/P&gt;
&lt;P&gt;index_fw-&amp;gt;index_general&lt;BR /&gt;index_window-&amp;gt;index_general&lt;BR /&gt;index_linux-&amp;gt;index_general&lt;BR /&gt;&lt;BR /&gt;2)If yes, this configuration needs to be done on HF or Indexer?&lt;BR /&gt;&lt;BR /&gt;3)if qns2 yes, which config file should be configured.&lt;/P&gt;</description>
    <pubDate>Mon, 30 Jan 2023 16:18:17 GMT</pubDate>
    <dc:creator>jack_lai</dc:creator>
    <dc:date>2023-01-30T16:18:17Z</dc:date>
    <item>
      <title>How to merge multiple index into single index?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-merge-multiple-index-into-single-index/m-p/628779#M15245</link>
      <description>&lt;P&gt;Hi splunk god,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Have enquiry, i have an environment which heavyforwarder logs send to cluster indexer.&lt;BR /&gt;I need the below multi index merge into single index which is index_general.&lt;BR /&gt;Basically, when user search index_general and able to search all the logs contain in the three index.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;1)Is this configuration feasible?&lt;/P&gt;
&lt;P&gt;index_fw-&amp;gt;index_general&lt;BR /&gt;index_window-&amp;gt;index_general&lt;BR /&gt;index_linux-&amp;gt;index_general&lt;BR /&gt;&lt;BR /&gt;2)If yes, this configuration needs to be done on HF or Indexer?&lt;BR /&gt;&lt;BR /&gt;3)if qns2 yes, which config file should be configured.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 16:18:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-merge-multiple-index-into-single-index/m-p/628779#M15245</guid>
      <dc:creator>jack_lai</dc:creator>
      <dc:date>2023-01-30T16:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: merge multiple index into single index</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-merge-multiple-index-into-single-index/m-p/628786#M15246</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253348"&gt;@jack_lai&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1) Yes, this can be done. But there are 2 things to consider.&lt;BR /&gt;1.1. Searches will be slower as you move 3 index data to one.&lt;BR /&gt;1.2. Data size of&amp;nbsp;&lt;SPAN&gt;index_general should be the sum of the data sizes of 3 indexes and data retention should be the maximum value of data retention values of 3 indexes.&lt;BR /&gt;&lt;BR /&gt;2) You can update inputs.conf on forwarders to send data to&amp;nbsp;&lt;STRONG&gt;index_general&lt;/STRONG&gt; index. But this will work only for new data.&lt;BR /&gt;&lt;BR /&gt;3) For existing data you can use the&amp;nbsp;&lt;STRONG&gt;collect&lt;/STRONG&gt; command to write data to the&amp;nbsp;&lt;STRONG&gt;index_general&lt;/STRONG&gt; index.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 06:38:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-merge-multiple-index-into-single-index/m-p/628786#M15246</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2023-01-30T06:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to merge multiple index into single index?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-merge-multiple-index-into-single-index/m-p/628946#M15257</link>
      <description>&lt;P&gt;How about if i got 2 cluster environments for example:&lt;BR /&gt;&lt;BR /&gt;HF1-&amp;gt;HF2&amp;gt;Indexer1&lt;BR /&gt;HF1-&amp;gt;HF2&amp;gt;Indexer2&lt;BR /&gt;&lt;BR /&gt;For Indexer1, the indexer should be able to query as per norm with 3 index.&lt;BR /&gt;For Indexer2, the indexer should be able to query with index_general.&lt;BR /&gt;&lt;BR /&gt;I have tried other option which props/transform from sourcetype with _MetaData:Index in HF1, but this method affects the existing index and logs flow to Indexer1 as well.&amp;nbsp; Is there any alternative option or technically feasible?&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 06:57:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-merge-multiple-index-into-single-index/m-p/628946#M15257</guid>
      <dc:creator>jack_lai</dc:creator>
      <dc:date>2023-01-31T06:57:20Z</dc:date>
    </item>
  </channel>
</rss>

