<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Importing older logs from s370's in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Importing-older-logs-from-s370-s/m-p/73449#M15052</link>
    <description>&lt;P&gt;This should help get you on the right track. There are a couple of options noted there (oneshot, batch) and details.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/919/what-is-the-best-way-to-load-archived-logs"&gt;http://splunk-base.splunk.com/answers/919/what-is-the-best-way-to-load-archived-logs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Example of the command here as well.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/5428/how-do-you-override-source-on-a-oneshot"&gt;http://splunk-base.splunk.com/answers/5428/how-do-you-override-source-on-a-oneshot&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jun 2012 19:40:26 GMT</pubDate>
    <dc:creator>sdaniels</dc:creator>
    <dc:date>2012-06-12T19:40:26Z</dc:date>
    <item>
      <title>Importing older logs from s370's</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Importing-older-logs-from-s370-s/m-p/73448#M15051</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;We purchased some s370's a number of months ago and after about a month or two we pointed the logs to an M670. We have now purchased Splunk for Ironport and want to take the logs from the S370's that existed before we pointed logging to the M670. How do we do that?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2012 19:20:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Importing-older-logs-from-s370-s/m-p/73448#M15051</guid>
      <dc:creator>brierw</dc:creator>
      <dc:date>2012-06-12T19:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Importing older logs from s370's</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Importing-older-logs-from-s370-s/m-p/73449#M15052</link>
      <description>&lt;P&gt;This should help get you on the right track. There are a couple of options noted there (oneshot, batch) and details.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/919/what-is-the-best-way-to-load-archived-logs"&gt;http://splunk-base.splunk.com/answers/919/what-is-the-best-way-to-load-archived-logs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Example of the command here as well.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/5428/how-do-you-override-source-on-a-oneshot"&gt;http://splunk-base.splunk.com/answers/5428/how-do-you-override-source-on-a-oneshot&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jun 2012 19:40:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Importing-older-logs-from-s370-s/m-p/73449#M15052</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-06-12T19:40:26Z</dc:date>
    </item>
  </channel>
</rss>

