The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: SplunkGeneral: Reindex existing data?

Previous Topic: Splunk bug with backslash and quotes - escape character \  |   Next Topic: Issues with external lookup fields from static file


Posts 1–3 of 3

Dear All,

Is it possible to reindex existing data? I had to move SPLUNK databases from one server to another.
The problem is that I seem to be unable to correctly extract fields. I was able to do this in the original server.

I thought it might have something to do with the fact that the databases came from a different server.

Is it possible to get SPLUNK to reindex data in its databases? I cannot just clean index as the data is only stored in SPLUNK DBs.

Any help appreciated.

Regards,

Michael

you can't manipulate/reindex in place the data that Splunk has already indexed.

what exactly is happening with respect to your problems extracting fields?

There should be no need to reindex. If you've copied the database (and data) that should be the most important thing. The other part you might need is the configuration if you didn't also copy that to your new machine.