Splunk Dev

Is is possible to split already indexed data in the main index to new indices?

sreerajms
Explorer

Our Splunk instance has indexed data from the last 1 year from various servers and is in use currently. Most of the data are indexed into the default 'main' index. Now, we would like to create some users with access to logs only from a particular a set of servers. Is it possible to split the already indexed data from this particular set of servers from the 'main' index to a new index so that I can grant the new users access only to the newly created index?

Tags (1)
0 Karma

HeinzWaescher
Motivator

Have you tried out to use restricted search terms from access controls -> roles for your users?

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...