Getting Data In

Migrating data from one index to another

Branden
Builder

I've been using the default "main" index for all my indexing. I'm at the point where I think it would be best to branch out a bit and have some separate indexes.

Suppose I create an index "access" which will store our web server access logs. Is there a way to migrate my existing access log data from the "main" index into the new "access" index? I don't want to have to specify two different indexes if/when I search for older access log information.

Thanks!

Tags (1)

gkanapathy
Splunk Employee
Splunk Employee

There is no need for you to do this. You can just make the old and the new indexes "default" for the user role(s).

Branden
Builder

Oh I see how to do it now. It's in the Roles section of the manager (duh).
Odd... when I try to create a new role, it won't let me add capabilities to the role. No matter what capabilities I select, it says the role only has 1 capability (delete by keyword). This happens even if I clone an existing role ('admin' in this case). Could this be a bug?

0 Karma

Branden
Builder

Just to clarify... are you saying I can configure it to search "access" and "main" by default without having to specify them in the search string?

0 Karma

hulahoop
Splunk Employee
Splunk Employee

This is the easiest way to combine your current access events in both the new and old indexes.

0 Karma

hulahoop
Splunk Employee
Splunk Employee

Unfortunately, there's no way to surgically transfer data from one index to another. If you want the existing access events in the main index, then you can delete them and re-index into the new access index.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Laser Bananas and Edge Hubs: Exploring Operational Technology (OT) Data Through a ...

  OT is a different environment to traditional IT and can have interesting challenges when interfacing the ...