Installation

How can I move Splunk logs into an alternative logging solution

kaustubhfab
Engager

Hello, Thank you for having me here.

I have a Enterprise license. I wish to move my existing logs which are in Splunk v5.0.1 into another logging solution.

I logged into Manager > Indexes and found that the in /mnt folder on an EBS. Just thinking out loud: Can I create an API endpoint that requests this data from Splunk?

If not, what alternatives I have to achieve that?

Thank you.

Tags (2)
0 Karma
1 Solution

aelliott
Motivator

kaustubhfab
Engager

Tried this as an example: curl -k -u admin:mypassword --data-urlencode search="search error" -d "output_mode=json" -d "count=10" -d "offset=0" -d "rf=sourcetype=rails" https://localhost:8001/servicesNS/admin/search/search/jobs/export Shouldnt I be getting 10 results? I get thousands of results.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...