Forums: SplunkGeneral: Reindex existing data?

Previous Topic: Splunk bug with backslash and quotes - escape character \  |   Next Topic: Issues with external lookup fields from static file


Posts 1–3 of 3  |  Post to this topic

Dear All,

Is it possible to reindex existing data? I had to move SPLUNK databases from one server to another.
The problem is that I seem to be unable to correctly extract fields. I was able to do this in the original server.

I thought it might have something to do with the fact that the databases came from a different server.

Is it possible to get SPLUNK to reindex data in its databases? I cannot just clean index as the data is only stored in SPLUNK DBs.

Any help appreciated.

Regards,

Michael

you can't manipulate/reindex in place the data that Splunk has already indexed.

what exactly is happening with respect to your problems extracting fields?

There should be no need to reindex. If you've copied the database (and data) that should be the most important thing. The other part you might need is the configuration if you didn't also copy that to your new machine.

Post to this topic

You must be logged in to post a reply.