<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error when importing event data in Reporting</title>
    <link>https://community.splunk.com/t5/Reporting/Error-when-importing-event-data/m-p/47067#M963</link>
    <description>&lt;P&gt;I want to move the data from one indexer to another one by merging them with existing data.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Sep 2012 17:01:49 GMT</pubDate>
    <dc:creator>tonopahtaos</dc:creator>
    <dc:date>2012-09-05T17:01:49Z</dc:date>
    <item>
      <title>Error when importing event data</title>
      <link>https://community.splunk.com/t5/Reporting/Error-when-importing-event-data/m-p/47065#M961</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;I want to export event data from one indexer and import them to another indexer.&lt;/P&gt;

&lt;P&gt;I used following command to export event data under 'main' index to a folder called 'events' under /tmp:&lt;/P&gt;

&lt;P&gt;/opt/splunk/bin/splunk export eventdata -index main -dir /tmp/events&lt;/P&gt;

&lt;P&gt;It has no problem.&lt;/P&gt;

&lt;P&gt;Then I created an NFS share for 'events' folder and mounted it to my second splunk indexer machine.  I can use 'ls /mnt/events' to see all files remotely.&lt;/P&gt;

&lt;P&gt;Then I used following command to import event data:&lt;/P&gt;

&lt;P&gt;./splunk import eventdata -index main -dir /mnt/events&lt;/P&gt;

&lt;P&gt;I got following error:&lt;/P&gt;

&lt;P&gt;The subcommand 'eventdata' is not valid for command 'import'.&lt;/P&gt;

&lt;P&gt;What is the problem here?  Why 'eventdata' is invalid during import when it is valid during export?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2012 00:39:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Error-when-importing-event-data/m-p/47065#M961</guid>
      <dc:creator>tonopahtaos</dc:creator>
      <dc:date>2012-08-30T00:39:02Z</dc:date>
    </item>
    <item>
      <title>Re: Error when importing event data</title>
      <link>https://community.splunk.com/t5/Reporting/Error-when-importing-event-data/m-p/47066#M962</link>
      <description>&lt;P&gt;If you're trying to move a whole index, you can just &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/admin/MoveAnIndex"&gt;move the index&lt;/A&gt; itself &lt;/P&gt;

&lt;P&gt;You can also rebuild an index if you need to merge data. Let me know if you need to.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2012 09:18:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Error-when-importing-event-data/m-p/47066#M962</guid>
      <dc:creator>dart</dc:creator>
      <dc:date>2012-09-05T09:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: Error when importing event data</title>
      <link>https://community.splunk.com/t5/Reporting/Error-when-importing-event-data/m-p/47067#M963</link>
      <description>&lt;P&gt;I want to move the data from one indexer to another one by merging them with existing data.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Sep 2012 17:01:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Error-when-importing-event-data/m-p/47067#M963</guid>
      <dc:creator>tonopahtaos</dc:creator>
      <dc:date>2012-09-05T17:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Error when importing event data</title>
      <link>https://community.splunk.com/t5/Reporting/Error-when-importing-event-data/m-p/47068#M964</link>
      <description>&lt;P&gt;The &lt;CODE&gt;splunk import&lt;/CODE&gt; command actually only supports the &lt;CODE&gt;userdata&lt;/CODE&gt; subcommand - it is &lt;EM&gt;not&lt;/EM&gt; designed to import event data. I have filed a documentation bug (reference SPL-56401) to clarify this fact in the CLI help.&lt;BR /&gt;
In my opinion, the best way to merge two indexes together is described in &lt;A href="http://wiki.splunk.com/Community:MoveIndexes"&gt;this Wiki topic&lt;/A&gt; &lt;STRONG&gt;- please pay special attention to the "Scrubbing the bucket IDs" section! -&lt;/STRONG&gt; and &lt;A href="http://splunk-base.splunk.com/answers/32176/is-it-possible-to-migrate-indexed-buckets-to-a-different-index-on-a-new-machine"&gt;this Splunk Answer&lt;/A&gt;. And &lt;A href="http://splunk-base.splunk.com/answers/3795/can-i-merge-data-buckets-from-multiple-indexes-or-indexers"&gt;this one&lt;/A&gt;, too.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2012 04:58:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Reporting/Error-when-importing-event-data/m-p/47068#M964</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2012-09-28T04:58:37Z</dc:date>
    </item>
  </channel>
</rss>

