Getting Data In

Migrating data from one index to another

Branden
Builder

I've been using the default "main" index for all my indexing. I'm at the point where I think it would be best to branch out a bit and have some separate indexes.

Suppose I create an index "access" which will store our web server access logs. Is there a way to migrate my existing access log data from the "main" index into the new "access" index? I don't want to have to specify two different indexes if/when I search for older access log information.

Thanks!

Tags (1)

gkanapathy
Splunk Employee
Splunk Employee

There is no need for you to do this. You can just make the old and the new indexes "default" for the user role(s).

Branden
Builder

Oh I see how to do it now. It's in the Roles section of the manager (duh).
Odd... when I try to create a new role, it won't let me add capabilities to the role. No matter what capabilities I select, it says the role only has 1 capability (delete by keyword). This happens even if I clone an existing role ('admin' in this case). Could this be a bug?

0 Karma

Branden
Builder

Just to clarify... are you saying I can configure it to search "access" and "main" by default without having to specify them in the search string?

0 Karma

hulahoop
Splunk Employee
Splunk Employee

This is the easiest way to combine your current access events in both the new and old indexes.

0 Karma

hulahoop
Splunk Employee
Splunk Employee

Unfortunately, there's no way to surgically transfer data from one index to another. If you want the existing access events in the main index, then you can delete them and re-index into the new access index.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...