Getting Data In

How to move index from main to custom index?

test_qweqwe
Builder

Hello
I failed and miss index for nginx and all logs saved to main.

Now I created new index "nginx_logs" and how me move all nginx logs from "main" to my new index "nginx_logs"?

Tags (2)
0 Karma
1 Solution

woodcock
Esteemed Legend

You can only move all of them or none of them. Here is the process to move EVERYTHING from index=main to NEW index=nginx:

On the forwarders, stop the Splunk instances so that they will not be sending ANYTHING to the Indexer(s). Update the inputs.conf so that your stuff is going to go to the new index when you start Splunk there.

On each indexer:
/opt/splunk/bin/splunk stop
Update /opt/splunk/etc/apps/*/indexes.conf to add the new nginx index.
cd /opt/splunk/var/lib/splunk/
mv -f main.dat nginx.dat
mv -f defaultdb nginx
/opt/splunk/bin/splunk start

When Splunk starts, it will create a new main index that is empty. Restart Splunk on the forwarder so it starts sending to the new index.

View solution in original post

woodcock
Esteemed Legend

You can only move all of them or none of them. Here is the process to move EVERYTHING from index=main to NEW index=nginx:

On the forwarders, stop the Splunk instances so that they will not be sending ANYTHING to the Indexer(s). Update the inputs.conf so that your stuff is going to go to the new index when you start Splunk there.

On each indexer:
/opt/splunk/bin/splunk stop
Update /opt/splunk/etc/apps/*/indexes.conf to add the new nginx index.
cd /opt/splunk/var/lib/splunk/
mv -f main.dat nginx.dat
mv -f defaultdb nginx
/opt/splunk/bin/splunk start

When Splunk starts, it will create a new main index that is empty. Restart Splunk on the forwarder so it starts sending to the new index.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...