Splunk Dev

Copy (not move) events into another index?

aworkman
Engager

I understand there's no way to do field extraction based on event types, but is there a way to COPY (not move) events into another index?

Tags (1)

shaa
Engager

hello! i was copy some data to new index with collect command but cipied data invisible. what wrong?

many thanks

dstricharz
Engager

Check out the command COLLECT. It allows you to specify a destination index while copying the result in events of your search.

jtrucks
Splunk Employee
Splunk Employee

You could export the results of a search matching the desired events to copy, then export in raw format (best done via CLI). Then you can use splunk add oneshot to index the data into the other index. This avoids messes with filenames et al.

You can export the events and then import them using the same sourcetype with:

splunk add oneshot yourdatafilenamehere -sourcetype yourdesiredsourcetypehere -index yourotherindexhere

Another option is to use a summary index instead, would be as easy as:

your event search here | collect index=yoursummaryindexnamehere

Perhaps elaborate on why you want to copy them to the other index? Also, is this on an ongoing basis or just once to copy historical data?

--
Jesse Trucks
Minister of Magic

mataharry
Communicator

You can copy the buckets from an index to another
- beware to avoid bucket id duplicates.
It will not be selective, all events will be present. But you can hide afterward using the "delete" command.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...