Dear All,
Is it possible to reindex existing data? I had to move SPLUNK databases from one server to another.
The problem is that I seem to be unable to correctly extract fields. I was able to do this in the original server.
I thought it might have something to do with the fact that the databases came from a different server.
Is it possible to get SPLUNK to reindex data in its databases? I cannot just clean index as the data is only stored in SPLUNK DBs.
Any help appreciated.
Regards,
Michael