Deployment Architecture

Migrate from one index to another index with data integrity control

lyukai
New Member

Hi All,

I recently have a new requirement to turn on data integrity control for a index ("X"). However, as the index already has data, I have to create a new index ("Y") and index incoming data into Y.

i read, https://answers.splunk.com/answers/32176/is-it-possible-to-migrate-indexed-buckets-to-a-different-in... but i'm not sure i can do this as the new index has data integrity control.

any advice on the best way i can migrate historical data from X to Y?

Thanks a million!

Best Regards,
Eric

0 Karma

davpx
Communicator

Have you thought about simply renaming the index and turning on data integrity control? After that you should be able to regenerate the hashes.

If this isn't an option for you, you'll have to replay the historical data from your forwarders by clearing the fishbucket once pointed to the new index, if that data it still exists.

https://answers.splunk.com/answers/28134/rename-an-index-in-4-1-8.html
https://docs.splunk.com/Documentation/Splunk/7.0.1/Security/Dataintegritycontrol#Regenerate_hashes

0 Karma

mayurr98
Super Champion
0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...