<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Recreate an indexed 'source' file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Recreate-an-indexed-source-file/m-p/43813#M8191</link>
    <description>&lt;P&gt;Check the splunk export command.&lt;/P&gt;

&lt;P&gt;./splunk export eventdata -index main -dir /tmp/events -host www -sourcetype syslog -terms "dhcp OR bind"&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2011 19:56:33 GMT</pubDate>
    <dc:creator>rroberts</dc:creator>
    <dc:date>2011-11-02T19:56:33Z</dc:date>
    <item>
      <title>Recreate an indexed 'source' file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Recreate-an-indexed-source-file/m-p/43810#M8188</link>
      <description>&lt;P&gt;Is there a way to extract the entire source file from the splunk index?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2011 18:30:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Recreate-an-indexed-source-file/m-p/43810#M8188</guid>
      <dc:creator>ironhalo</dc:creator>
      <dc:date>2011-07-15T18:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: Recreate an indexed 'source' file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Recreate-an-indexed-source-file/m-p/43811#M8189</link>
      <description>&lt;P&gt;Can you explain more about the use-case?  There isn't a single file once it's indexed within Splunk.  But, you can conduct an appropriate search and then click on the little down arrow to the left of the timestamp and click "View Source" to see the raw events.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2011 18:38:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Recreate-an-indexed-source-file/m-p/43811#M8189</guid>
      <dc:creator>mw</dc:creator>
      <dc:date>2011-07-15T18:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: Recreate an indexed 'source' file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Recreate-an-indexed-source-file/m-p/43812#M8190</link>
      <description>&lt;P&gt;The process in question continually generates a lot of log information, once the log file reaches a certain size it's written over. I've tried to 'view source', but it returns an error. I figured the next best solution would be to try and re create the log file entirely.  These log files can be tens of thousands of lines.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2011 19:49:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Recreate-an-indexed-source-file/m-p/43812#M8190</guid>
      <dc:creator>ironhalo</dc:creator>
      <dc:date>2011-07-15T19:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: Recreate an indexed 'source' file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Recreate-an-indexed-source-file/m-p/43813#M8191</link>
      <description>&lt;P&gt;Check the splunk export command.&lt;/P&gt;

&lt;P&gt;./splunk export eventdata -index main -dir /tmp/events -host www -sourcetype syslog -terms "dhcp OR bind"&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2011 19:56:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Recreate-an-indexed-source-file/m-p/43813#M8191</guid>
      <dc:creator>rroberts</dc:creator>
      <dc:date>2011-11-02T19:56:33Z</dc:date>
    </item>
  </channel>
</rss>

