Getting Data In

Reroute host to different index

troy44112
Explorer

I am trying to figure out how to reroute a specific host to a different index.
For example, search results of host=1234test shows in index=best_life...
How would I change the index of host1234 from best_life to fall into a different index that exist already ie. (index=other_index)..

Labels (1)
0 Karma

ashvinpandey
Contributor

@troy44112 

Use props.conf and transforms.conf for this..

 

 #props.conf
 [source]
 TRANSFORMS-routing_for_norris_index = route_to_norris_index

 #transforms.conf
 [route_to_norris_index]
 DEST_KEY = _MetaData:Index
 REGEX = chuck
 FORMAT = norris

 

This will route all events containing chuck into the norris index.


please find the below link for more detailed info:
https://blog.avotrix.com/implement-split-indexing-in-splunk/ 
Also, If this reply helps you, an upvote would be appreciated.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check the inputs.conf files on that host.  Change all instances of "index=best_life" to "index=other_index" and restart Splunk on that host.

Data that is already in index=best_life cannot be moved, but you can use the collect command to copy events to another index.  This will affect your license usage.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...