Hello everyone,
I have been trying to move data from my old 6.3.2 splunk to the new 8.1.3 splunk which is empty.
I tried to first do a search "*" and downloaded everything which is 16gb. I then used the new splunk web gui monitor import which did take all the data, but it only had one host, source, and source type.
The original splunk had 3 index names, 2 hosts sending data, and many sources and source types.
How can i move the data so that search results show the same as it did in the original splunk?
Is there a way to export everything to match exactly? I am having a hard time determining how to move these items.
Both the new and old splunk have 1 search head, 2 indexers, and one master. I am not familair in how I can copy the index folder method either. Hopefully someone can guide me in how I can move the data in place keeping all the hosts, source, sourcetypes, etc.
Thanks
Hi @akballow,
one question: have you already data on the new installation?
if not, you can copy the indexes folders in the new installation (obviously when Splunk is not running) and you have the data in the new installation, you have only to put attention to the folder location in indexes.conf.
Otherwise, you have to extract the data with the following annoying procedure:
Ciao.
Giuseppe