Splunk Search

Extract logs for specific host in cold buckets

adidibra
Loves-to-Learn
Hello, I need to move old logs for a specific logsource(host) to be indexed in another splunk cluster. When I use the dbinspect in the actual splunk cluster, for that specific index, the logs seems to be in the cold buckets. Is it possible to extract logs of a specific host from cold buckets so it can be moved to another splunk cluster?
Labels (1)
0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!