Getting Data In

Move events from an index to another one

rbw78
Communicator

Hello

I search could i move sepcific data from an index called index1 to another one called index2.

Let's say i have all this kind of events in my index 1 :
Events kind 1
Events kind 2
Events kind 3
Events kind 4

I want to move all the events 3 & 4 to index index2 and delete them from index1.

So the final result would be :
Index1 :
Events kind 1
Events kind 2

Index2 :
Events kind 3
Events kind 4

Is there a way to do that ?

Thanks.

Tags (3)
0 Karma

jonuwz
Influencer

I'm guessing this is a 1 off and you don't have the raw data inputs anymore ?

If thats true,

If index2 does not exist already, by far the easiest solution would be to make a copy of index1 called index2, delete everything but kind3 and kind4 from index2, then delete kind3 and kind4 from index1.

If index2 exists already and you're wearing your rubber safety pants, you could try this :

  1. make a copy of index1 called index3
  2. delete everything but kind3 and kind4 from index3
  3. merge index3's buckets into index2
  4. delete index3
  5. deleting kind3 and kind4 from index1

It goes without saying, backup your indexes 1st, and please report back if it works : )

You are going to waste a lot of space though, deleting data from an index doesn't free up space, it just marks it as deleted.

Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...