You can't really rename an index, but you can create a new index with the name you want (via indexes.conf/GUI) and move the data from the old index to the new index.
You would need to stop Splunk, then move the $SPLUNK_DB/<old_index>
directory to $SPLUNK_DB/<new_index>
and then start Splunk. That should be all you'd need to do to get the data in the new index. Keep in mind any searches that reference the other index will need to be changed.
You can't really rename an index, but you can create a new index with the name you want (via indexes.conf/GUI) and move the data from the old index to the new index.
You would need to stop Splunk, then move the $SPLUNK_DB/<old_index>
directory to $SPLUNK_DB/<new_index>
and then start Splunk. That should be all you'd need to do to get the data in the new index. Keep in mind any searches that reference the other index will need to be changed.
Is Splunk gonna charge us for this move?
No. This administrative procedure moves the index files "underneath the hood" so to speak. The files are already parsed and do not go through the parsing/indexing phase again. Thus, no license meter.
Glad to hear that it worked, be sure to click the check box to accept the answer so it will show as you accepting it.
Worked like a charm. Thank you.