<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to recreate partial index data with metadata on different Splunk installation? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-recreate-partial-index-data-with-metadata-on-different/m-p/654939#M111002</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;basically you could try to copy those from prod node. Here is an old post about it&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Installation/How-to-migrate-indexes-to-new-indexer-instance/m-p/528064/highlight/true" target="_blank"&gt;https://community.splunk.com/t5/Installation/How-to-migrate-indexes-to-new-indexer-instance/m-p/528064/highlight/true&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You should change needed configurations after copy as you want this to be a different host &amp;nbsp;also you should copy only needed indexes or remove those after rsync.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Aug 2023 20:31:58 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2023-08-18T20:31:58Z</dc:date>
    <item>
      <title>How to recreate partial index data with metadata on different Splunk installation?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-recreate-partial-index-data-with-metadata-on-different/m-p/654924#M111001</link>
      <description>&lt;P&gt;I have a Splunk container for development (Dev).&amp;nbsp; I want to import a slice of data from one index of my production Splunk (Prod) to this container so I can write searches against that data exactly as it appears in Prod.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using Export on Prod and Import on Dev is not producing my desired outcome.&amp;nbsp; Doing this as a single file with a single indexing is creating logs that are indexing the container hostname as the host not the host of the data itself.&amp;nbsp; The data in the Prod index is of varying sourcetypes so the import is also only creating the sourcetype of the import file, not tha sourcetype from the data itself.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking at possibly using the&amp;nbsp; EventGen app but not sure if this will do what I'm trying to do.&lt;/P&gt;&lt;P&gt;Is what I'm doing possible?&amp;nbsp; I do not want the entire prod index. I do not want to rsync or otherwise go to the backend to move data.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EDIT: I modified the title, it seems I want the raw data and metadata to all come over in one package?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 18:22:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-recreate-partial-index-data-with-metadata-on-different/m-p/654924#M111001</guid>
      <dc:creator>deepdive100</dc:creator>
      <dc:date>2023-08-18T18:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to recreate partial index data with metadata on different Splunk installation?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-recreate-partial-index-data-with-metadata-on-different/m-p/654939#M111002</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;basically you could try to copy those from prod node. Here is an old post about it&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Installation/How-to-migrate-indexes-to-new-indexer-instance/m-p/528064/highlight/true" target="_blank"&gt;https://community.splunk.com/t5/Installation/How-to-migrate-indexes-to-new-indexer-instance/m-p/528064/highlight/true&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You should change needed configurations after copy as you want this to be a different host &amp;nbsp;also you should copy only needed indexes or remove those after rsync.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 20:31:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-recreate-partial-index-data-with-metadata-on-different/m-p/654939#M111002</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-08-18T20:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to recreate partial index data with metadata on different Splunk installation?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-recreate-partial-index-data-with-metadata-on-different/m-p/655335#M111038</link>
      <description>&lt;P&gt;So it seems the way forward for me is to write some scripts to pull down `index=app host=each_host sourcetype=each_sourcetype` for a specific time block, export them with the hostname in the title and import each with the hostname widget set to the filename.&amp;nbsp; One script of API calls with the variables on the hosts and sourcetype should do it.&amp;nbsp; Will try it out and update here&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 13:53:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-recreate-partial-index-data-with-metadata-on-different/m-p/655335#M111038</guid>
      <dc:creator>deepdive100</dc:creator>
      <dc:date>2023-08-23T13:53:57Z</dc:date>
    </item>
  </channel>
</rss>

