Deployment Architecture

Migrating data from main index to new index in splunk cloud

rajiv_r
Explorer

I have pushed all my sourcetype in the main index since it was streaming through single app. Now i required to move the data from main index to a new index and i am using splunk cloud instance. So can anyone please help in migrating the data from main index to the new index in splunk cloud instance

Tags (1)
0 Karma

anmolpatel
Builder
0 Karma

rajiv_r
Explorer

Yes anmol, i have already seen those links. It dint help me as all of them have given the guidelines for the splunk enterprise version not for the splunk self service cloud deployment. Splunk cloud deployment does not have an access to the folder structure to copy and paste the main index data to the new index.

0 Karma

anmolpatel
Builder

@rajiv_r apologies, i missed the tag. As per the Splunk docs, user doesn't have the permission to migrate or move indexes:
https://docs.splunk.com/Documentation/SplunkCloud/8.0.2001/User/ManageIndexes

you would want to raise a Support ticket for that if you want to move all data.

Alternatively, if you want to push some data across to a new index, you can create the new index and use the collect command. This will put the data into the summary index.

Get Updates on the Splunk Community!

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...

Hunt Smarter, Not Harder: Discover New SPL “Recipes” in Our Threat Hunting Webinar

Are you ready to take your threat hunting skills to the next level? As Splunk community members, you know the ...