Deployment Architecture

Migrating data from main index to new index in splunk cloud

rajiv_r
Explorer

I have pushed all my sourcetype in the main index since it was streaming through single app. Now i required to move the data from main index to a new index and i am using splunk cloud instance. So can anyone please help in migrating the data from main index to the new index in splunk cloud instance

Tags (1)
0 Karma

anmolpatel
Builder
0 Karma

rajiv_r
Explorer

Yes anmol, i have already seen those links. It dint help me as all of them have given the guidelines for the splunk enterprise version not for the splunk self service cloud deployment. Splunk cloud deployment does not have an access to the folder structure to copy and paste the main index data to the new index.

0 Karma

anmolpatel
Builder

@rajiv_r apologies, i missed the tag. As per the Splunk docs, user doesn't have the permission to migrate or move indexes:
https://docs.splunk.com/Documentation/SplunkCloud/8.0.2001/User/ManageIndexes

you would want to raise a Support ticket for that if you want to move all data.

Alternatively, if you want to push some data across to a new index, you can create the new index and use the collect command. This will put the data into the summary index.

Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...