<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data copied from one index to another index in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654609#M226154</link>
    <description>&lt;P&gt;You can use the collect command to write to another index, but first I would question, why would you want to do this? What is it that you are trying to do that means you need a copy of the data in another index?&lt;/P&gt;</description>
    <pubDate>Thu, 17 Aug 2023 07:05:04 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2023-08-17T07:05:04Z</dc:date>
    <item>
      <title>How to copy data from one index to another index?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654605#M226152</link>
      <description>&lt;P&gt;What will be the query to copy&amp;nbsp; all data from one index to another index in splunk ,we are using splunk for jenkins logs&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 18:02:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654605#M226152</guid>
      <dc:creator>welcome</dc:creator>
      <dc:date>2023-08-17T18:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: Data copied from one index to another index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654607#M226153</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259737"&gt;@welcome&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;there's no reasons to copy events from an index to another: indexes arent database's tables, they are silos in which store events with the same access rights and the same retention.&lt;/P&gt;&lt;P&gt;Why do you want to copy events from an index into another?&lt;/P&gt;&lt;P&gt;Anyway, there isn't a copy command, you can make a copy of the entire events or of some extracted fields from an index to another using the collect command (&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.0/SearchReference/Collect" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.0/SearchReference/Collect&lt;/A&gt;) that's usually used for Summary indexes.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 07:02:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654607#M226153</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-08-17T07:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Data copied from one index to another index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654609#M226154</link>
      <description>&lt;P&gt;You can use the collect command to write to another index, but first I would question, why would you want to do this? What is it that you are trying to do that means you need a copy of the data in another index?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 07:05:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654609#M226154</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-17T07:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Data copied from one index to another index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654610#M226155</link>
      <description>&lt;P&gt;Just for the copy&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 07:08:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654610#M226155</guid>
      <dc:creator>welcome</dc:creator>
      <dc:date>2023-08-17T07:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: Data copied from one index to another index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654613#M226156</link>
      <description>&lt;P&gt;I am using collect command but some data is missing, can you give me proper query&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 07:13:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654613#M226156</guid>
      <dc:creator>welcome</dc:creator>
      <dc:date>2023-08-17T07:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: Data copied from one index to another index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654615#M226157</link>
      <description>&lt;P&gt;Which data is missing? Is it whole events or some fields in all events or some fields in some events? What characterises the missing data?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 07:16:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654615#M226157</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-17T07:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Data copied from one index to another index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654616#M226158</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/259737"&gt;@welcome&lt;/a&gt;&lt;/P&gt;&lt;P&gt;please try something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=your_orig_index
| table _time _raw
| collect index=new_index&lt;/LI-CODE&gt;&lt;P&gt;but there isn't any reason to do this!&lt;/P&gt;&lt;P&gt;ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2023 07:17:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654616#M226158</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-08-17T07:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Data copied from one index to another index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654845#M226209</link>
      <description>&lt;P&gt;Not all events only some events, suppose when we see in events section we have some fields ,in that&amp;nbsp; we can see build related fileds ,we cant get the exact number of build fileds ,Job urls&amp;nbsp; and job names etc....&amp;nbsp; as in previous index ,can you please give me proper answer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 11:45:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654845#M226209</guid>
      <dc:creator>welcome</dc:creator>
      <dc:date>2023-08-18T11:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Data copied from one index to another index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654846#M226210</link>
      <description>&lt;P&gt;You keep asking for a proper answer, but you haven't really given a proper question, or at least one that can be answered in a meaningful way.&lt;/P&gt;&lt;P&gt;What events did you start with?&lt;/P&gt;&lt;P&gt;What events have you copied?&lt;/P&gt;&lt;P&gt;Which events did not get copied?&lt;/P&gt;&lt;P&gt;How did you do the copy?&lt;/P&gt;&lt;P&gt;Once we know what it is you are dealing with, and what you have already tried, we might be able to advise you further.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Aug 2023 11:44:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/654846#M226210</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-18T11:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Data copied from one index to another index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/655110#M226311</link>
      <description>&lt;P&gt;This is the query i have tried:&amp;nbsp; &amp;nbsp; index=A source=sourceA host=hostA | collect index=B source=sourceA sourcetype=sourcetypeA host=hostA&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;when I select for specific time range suppose from april1 to april 30, suppose there are 2 lakh events in indexA but I am getting only 1 lakh events into indexB ,I don't know why some events are missing.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 06:38:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/655110#M226311</guid>
      <dc:creator>welcome</dc:creator>
      <dc:date>2023-08-22T06:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: Data copied from one index to another index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/655119#M226313</link>
      <description>&lt;P&gt;There is possibly a limit to the number of events you can add to the summary index at any one time. Try running from Apr 1 to Apr 15, and then again from Apr 16 to Apr 30, or even Apr 1 to Apr 10, Apr 11 to Apr 20 and Apr 21 to Apr 30&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 07:02:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-copy-data-from-one-index-to-another-index/m-p/655119#M226313</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-08-22T07:02:51Z</dc:date>
    </item>
  </channel>
</rss>

