Getting Data In

Migrating data from one index to another

Branden
Builder

I've been using the default "main" index for all my indexing. I'm at the point where I think it would be best to branch out a bit and have some separate indexes.

Suppose I create an index "access" which will store our web server access logs. Is there a way to migrate my existing access log data from the "main" index into the new "access" index? I don't want to have to specify two different indexes if/when I search for older access log information.

Thanks!

Tags (1)

gkanapathy
Splunk Employee
Splunk Employee

There is no need for you to do this. You can just make the old and the new indexes "default" for the user role(s).

Branden
Builder

Oh I see how to do it now. It's in the Roles section of the manager (duh).
Odd... when I try to create a new role, it won't let me add capabilities to the role. No matter what capabilities I select, it says the role only has 1 capability (delete by keyword). This happens even if I clone an existing role ('admin' in this case). Could this be a bug?

0 Karma

Branden
Builder

Just to clarify... are you saying I can configure it to search "access" and "main" by default without having to specify them in the search string?

0 Karma

hulahoop
Splunk Employee
Splunk Employee

This is the easiest way to combine your current access events in both the new and old indexes.

0 Karma

hulahoop
Splunk Employee
Splunk Employee

Unfortunately, there's no way to surgically transfer data from one index to another. If you want the existing access events in the main index, then you can delete them and re-index into the new access index.

Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...