Other Usage

Exporting data and importing into another Splunk instance

CSReviews
Loves-to-Learn

I am planning on teaching others how to use Splunk to search through data, similar to the Splunk boss of the soc challenges-

https://github.com/splunk/botsv3

Similarly, I would like to export the data I generated in my Splunk instance to then have students import into there's to follow along. The only way I can figure out how to do this is from running a search and using the export feature. Is there a recommendation for this? 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

there some apps, which you could use to generate continuously sample data. Probably mostly used is eventgen https://splunkbase.splunk.com/app/1924

One option is just e.g. tar that index and untar it on target systems. Of course you need to do also app for defining it on those target systems. This needs that those nodes are enough equal like same Linux etc. If I recall right something like this was done for those older bots datasets?

r. Ismo

0 Karma

splunkreal
Motivator

Hello @CSReviews you can export as csv file it's then easy to import.

https://hurricanelabs.com/splunk-tutorials/ingesting-a-csv-file-into-splunk/

"Upload with Splunk Web"

 

 

* If this helps, please upvote or accept solution if it solved *
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...