<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Move data from old Splunk 6.3.2 to New Splunk 8.1.3 help in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Move-data-from-old-Splunk-6-3-2-to-New-Splunk-8-1-3-help/m-p/558928#M92463</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236254"&gt;@akballow&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;one question: have you already data on the new installation?&lt;/P&gt;&lt;P&gt;if not, you can copy the indexes folders in the new installation (obviously when Splunk is not running) and you have the data in the new installation, you have only to put attention to the folder location in indexes.conf.&lt;/P&gt;&lt;P&gt;Otherwise, you have to extract the data with the following annoying procedure:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;analyze if in your searches are relevant source and host fields,&lt;/LI&gt;&lt;LI&gt;if not:&lt;UL&gt;&lt;LI&gt;extract data in raw format for each sourcetype and index you have (index=index1 sourcetype=sourcetype1),&lt;/LI&gt;&lt;LI&gt;annotate for each extraction index and sourcetype,&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;if yes:&lt;UL&gt;&lt;LI&gt;extract data in raw format for each sourcetype, index, host and source you have (index=index1 sourcetype=sourcetype1 source=source1 host=host1),&lt;/LI&gt;&lt;LI&gt;annotate for each extraction index, sourcetype, host and source,&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;upload one by one the data in the new system using the above information.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Sat, 10 Jul 2021 06:13:24 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-07-10T06:13:24Z</dc:date>
    <item>
      <title>Move data from old Splunk 6.3.2 to New Splunk 8.1.3 help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Move-data-from-old-Splunk-6-3-2-to-New-Splunk-8-1-3-help/m-p/558913#M92462</link>
      <description>&lt;P&gt;Hello everyone,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have been trying to move data from my old 6.3.2 splunk to the new 8.1.3 splunk which is empty.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to first do a search "*" and downloaded everything which is 16gb. I then used the new splunk web gui monitor import which did take all the data, but it only had one host, source, and source type.&lt;BR /&gt;&lt;BR /&gt;The original splunk had 3 index names, 2 hosts sending data, and many sources and source types.&lt;BR /&gt;&lt;BR /&gt;How can i move the data so that search results show the same as it did in the original splunk?&lt;BR /&gt;&lt;BR /&gt;Is there a way to export everything to match exactly? I am having a hard time determining how to move these items.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Both the new and old splunk have 1 search head, 2 indexers, and one master. I am not familair in how I can copy the index folder method either. Hopefully someone can guide me in how I can move the data in place keeping all the hosts, source, sourcetypes, etc.&lt;BR /&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 22:37:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Move-data-from-old-Splunk-6-3-2-to-New-Splunk-8-1-3-help/m-p/558913#M92462</guid>
      <dc:creator>akballow</dc:creator>
      <dc:date>2021-07-09T22:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: Move data from old Splunk 6.3.2 to New Splunk 8.1.3 help</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Move-data-from-old-Splunk-6-3-2-to-New-Splunk-8-1-3-help/m-p/558928#M92463</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236254"&gt;@akballow&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;one question: have you already data on the new installation?&lt;/P&gt;&lt;P&gt;if not, you can copy the indexes folders in the new installation (obviously when Splunk is not running) and you have the data in the new installation, you have only to put attention to the folder location in indexes.conf.&lt;/P&gt;&lt;P&gt;Otherwise, you have to extract the data with the following annoying procedure:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;analyze if in your searches are relevant source and host fields,&lt;/LI&gt;&lt;LI&gt;if not:&lt;UL&gt;&lt;LI&gt;extract data in raw format for each sourcetype and index you have (index=index1 sourcetype=sourcetype1),&lt;/LI&gt;&lt;LI&gt;annotate for each extraction index and sourcetype,&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;if yes:&lt;UL&gt;&lt;LI&gt;extract data in raw format for each sourcetype, index, host and source you have (index=index1 sourcetype=sourcetype1 source=source1 host=host1),&lt;/LI&gt;&lt;LI&gt;annotate for each extraction index, sourcetype, host and source,&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;upload one by one the data in the new system using the above information.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jul 2021 06:13:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Move-data-from-old-Splunk-6-3-2-to-New-Splunk-8-1-3-help/m-p/558928#M92463</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-07-10T06:13:24Z</dc:date>
    </item>
  </channel>
</rss>

