I did extract Splunk logs from a different Splunk instance using curl export method with the following information in the csv format | table index, sourcetype, source, host, _raw I got nearly some 5GB data. Is there any way I can import this data in another Splunk instance's HF so that the data get auto aligned to the right index, sourcetype, source and host? Currently, I am trying the add data from the console which allows 500mb but it request manually choose the sourcetype, index and other settings before importing.
... View more