<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Export/Reindex 500GB in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Export-Reindex-500GB/m-p/243916#M99102</link>
    <description>&lt;P&gt;This is perfect. Thank you!&lt;/P&gt;</description>
    <pubDate>Wed, 24 Aug 2016 15:45:59 GMT</pubDate>
    <dc:creator>ckillg</dc:creator>
    <dc:date>2016-08-24T15:45:59Z</dc:date>
    <item>
      <title>Export/Reindex 500GB</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Export-Reindex-500GB/m-p/243914#M99100</link>
      <description>&lt;P&gt;I'm trying to figure out the best way to send most of a 500GB index back through the &lt;STRONG&gt;Heavy Forwarder -&amp;gt; Indexer Cluster&lt;/STRONG&gt; chain to correct hostname and sourcetype issues. &lt;/P&gt;

&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 15:04:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Export-Reindex-500GB/m-p/243914#M99100</guid>
      <dc:creator>ckillg</dc:creator>
      <dc:date>2016-08-24T15:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: Export/Reindex 500GB</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Export-Reindex-500GB/m-p/243915#M99101</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;

&lt;P&gt;If you have a reasonable number of index/sourcetype/host combinations you can run an indivual export by combination through the api:&lt;/P&gt;

&lt;P&gt;Example curl command from the HF (to export the file locally to the HF):&lt;/P&gt;

&lt;P&gt;sudo curl -k -u admin:password &lt;A href="https://splunksh:8089/services/search/jobs/export" target="_blank"&gt;https://splunksh:8089/services/search/jobs/export&lt;/A&gt; --data-urlencode search='search index=myindex sourcetype=mysourcetype host=myhost earliest=0 latest=now' -d output_mode=raw -o myindex_myhost_mysourcetype.txt&lt;/P&gt;

&lt;P&gt;Then, create monitor stanzas in the HF with the appropiate index, sourcetype and host values for each file. You could also create transforms to get those meta data from the file name, but that will be more complex, for doing it just once&lt;/P&gt;

&lt;P&gt;Hope this helps&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:43:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Export-Reindex-500GB/m-p/243915#M99101</guid>
      <dc:creator>gfuente</dc:creator>
      <dc:date>2020-09-29T10:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Export/Reindex 500GB</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Export-Reindex-500GB/m-p/243916#M99102</link>
      <description>&lt;P&gt;This is perfect. Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 15:45:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Export-Reindex-500GB/m-p/243916#M99102</guid>
      <dc:creator>ckillg</dc:creator>
      <dc:date>2016-08-24T15:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Export/Reindex 500GB</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Export-Reindex-500GB/m-p/243917#M99103</link>
      <description>&lt;P&gt;Forgot to say, that you need to ensure that the HF has the appropiate props configurations for the sourctypes you want to reindex.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 06:44:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Export-Reindex-500GB/m-p/243917#M99103</guid>
      <dc:creator>gfuente</dc:creator>
      <dc:date>2016-08-25T06:44:02Z</dc:date>
    </item>
  </channel>
</rss>

