Installation

How can I move Splunk logs into an alternative logging solution

kaustubhfab
Engager

Hello, Thank you for having me here.

I have a Enterprise license. I wish to move my existing logs which are in Splunk v5.0.1 into another logging solution.

I logged into Manager > Indexes and found that the in /mnt folder on an EBS. Just thinking out loud: Can I create an API endpoint that requests this data from Splunk?

If not, what alternatives I have to achieve that?

Thank you.

Tags (2)
0 Karma
1 Solution

aelliott
Motivator

kaustubhfab
Engager

Tried this as an example: curl -k -u admin:mypassword --data-urlencode search="search error" -d "output_mode=json" -d "count=10" -d "offset=0" -d "rf=sourcetype=rails" https://localhost:8001/servicesNS/admin/search/search/jobs/export Shouldnt I be getting 10 results? I get thousands of results.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...