Getting Data In

Migrating data from one index to another

Branden
Builder

I've been using the default "main" index for all my indexing. I'm at the point where I think it would be best to branch out a bit and have some separate indexes.

Suppose I create an index "access" which will store our web server access logs. Is there a way to migrate my existing access log data from the "main" index into the new "access" index? I don't want to have to specify two different indexes if/when I search for older access log information.

Thanks!

Tags (1)

gkanapathy
Splunk Employee
Splunk Employee

There is no need for you to do this. You can just make the old and the new indexes "default" for the user role(s).

Branden
Builder

Oh I see how to do it now. It's in the Roles section of the manager (duh).
Odd... when I try to create a new role, it won't let me add capabilities to the role. No matter what capabilities I select, it says the role only has 1 capability (delete by keyword). This happens even if I clone an existing role ('admin' in this case). Could this be a bug?

0 Karma

Branden
Builder

Just to clarify... are you saying I can configure it to search "access" and "main" by default without having to specify them in the search string?

0 Karma

hulahoop
Splunk Employee
Splunk Employee

This is the easiest way to combine your current access events in both the new and old indexes.

0 Karma

hulahoop
Splunk Employee
Splunk Employee

Unfortunately, there's no way to surgically transfer data from one index to another. If you want the existing access events in the main index, then you can delete them and re-index into the new access index.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Data Management Digest – August 2026

MichelleCorpora_1-1788182384472.png Welcome to the August 2026 edition of Data Management Digest! August was a ...

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...