Hello all,
I am trying to upload data I downloaded earlier from Splunk with the same exact fields as the original.
1) Which of the following formats should I export the data: raw, csv, xml, json?
2) When uploading again to Splunk, how can I make it looks like the same way as the original?
Showing a picture as an example:
Thanks a lot!
Hi @isaacmichaan,
it's a long job! I did it.
The best approach is to run a search on your old indexes for host, index and sourcetype
index=your_index sourcetype=your-sourcetype host=your_host
export them in raw format and manually upload them in the new sistem.
Then reapeat for different indexes, sourcetypes and hosts.
Ciao.
giuseppe