Getting Data In

Migrating data from one index to another

Branden
Builder

I've been using the default "main" index for all my indexing. I'm at the point where I think it would be best to branch out a bit and have some separate indexes.

Suppose I create an index "access" which will store our web server access logs. Is there a way to migrate my existing access log data from the "main" index into the new "access" index? I don't want to have to specify two different indexes if/when I search for older access log information.

Thanks!

Tags (1)

gkanapathy
Splunk Employee
Splunk Employee

There is no need for you to do this. You can just make the old and the new indexes "default" for the user role(s).

Branden
Builder

Oh I see how to do it now. It's in the Roles section of the manager (duh).
Odd... when I try to create a new role, it won't let me add capabilities to the role. No matter what capabilities I select, it says the role only has 1 capability (delete by keyword). This happens even if I clone an existing role ('admin' in this case). Could this be a bug?

0 Karma

Branden
Builder

Just to clarify... are you saying I can configure it to search "access" and "main" by default without having to specify them in the search string?

0 Karma

hulahoop
Splunk Employee
Splunk Employee

This is the easiest way to combine your current access events in both the new and old indexes.

0 Karma

hulahoop
Splunk Employee
Splunk Employee

Unfortunately, there's no way to surgically transfer data from one index to another. If you want the existing access events in the main index, then you can delete them and re-index into the new access index.

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...