Getting Data In

What is the best way to upload exported Splunk data into another Splunk instance?

aoliullah
Path Finder

Hi. I have tried to export large number of events from a Splunk instance to another instance to work with the data (i.e.create dashboards etc). When I tried to upload the exported csv file into the Splunk instance, it looks messed up in the data preview. They are all from known sources (i.e. iis data, win event logs etc). How do i correct this? Or is there any better way to do it?

0 Karma
1 Solution

DalJeanis
Legend

If you want the data to look exactly the same, you really need to have it ingested in the same way. That means your target machine must have all the same configurations to extract and transform the data.

Also, make sure that you are exporting the _raw, as opposed to a formatted CSV file of the pre-chewed information.

Here's a useful link -
https://answers.splunk.com/answers/88107/export-index-data-from-production-splunk-and-import-intotes...

Here's a very in-depth explanation and cookbook, which you may or may not be able to follow completely depending on how much authority you have in the two systems -
https://answers.splunk.com/answers/25174/how-to-export-import-events-from-indexes.html

View solution in original post

aaraneta_splunk
Splunk Employee
Splunk Employee

@aoliullah - Did the answer provided by DalJeanis help provide a working solution to your question? If yes, please don't forget to resolve this post by clicking "Accept". If no, please leave a comment with more feedback. Thanks!

0 Karma

DalJeanis
Legend

If you want the data to look exactly the same, you really need to have it ingested in the same way. That means your target machine must have all the same configurations to extract and transform the data.

Also, make sure that you are exporting the _raw, as opposed to a formatted CSV file of the pre-chewed information.

Here's a useful link -
https://answers.splunk.com/answers/88107/export-index-data-from-production-splunk-and-import-intotes...

Here's a very in-depth explanation and cookbook, which you may or may not be able to follow completely depending on how much authority you have in the two systems -
https://answers.splunk.com/answers/25174/how-to-export-import-events-from-indexes.html

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...