Hi,
Is it possible to extract the complete data from the splunk? If so could you please tell me how to do that? This is not for small data that I can extract using search, we want to extract complete data from SPLUNK in specified format (NOT in files).
Thanks
Could exporttool be what you're looking for?
I didn't see a specific doc page for it, but you might get the information you need out here: http://answers.splunk.com/questions/2420/move-logs-to-another-index
This might also be of assistance: http://answers.splunk.com/questions/5757/export-raw-logs-from-splunk