Hi,
We purchased some s370's a number of months ago and after about a month or two we pointed the logs to an M670. We have now purchased Splunk for Ironport and want to take the logs from the S370's that existed before we pointed logging to the M670. How do we do that?
This should help get you on the right track. There are a couple of options noted there (oneshot, batch) and details.
http://splunk-base.splunk.com/answers/919/what-is-the-best-way-to-load-archived-logs
Example of the command here as well.
http://splunk-base.splunk.com/answers/5428/how-do-you-override-source-on-a-oneshot