Hi all,
Is there a way to combine a search command or dashboard XML along with the indexer data and export it so that it can be imported at another Splunk instance ? This would be helpful for scenarios where a Splunk user wants to see the behavior of Splunk search with indexed data on some other Splunk instance for troubleshooting purposes ?
I admit that this would also introduce issues like indexes to be presented on the new Splunk instance but I assume that the solution will take care of this.
Note : I initially searched Splunk answers for this. I got two threads namely [https://answers.splunk.com/answers/221798/exportimport-splunk-project.html][1] and [https://answers.splunk.com/answers/88107/export-index-data-from-production-splunk-and-import-intotest-instance-of-splunk.html][2] . While they almost match my scenario, the only difference is that I want a Splunk command or an option in GUI as the solution. I don't want to copy directories from one instance to another which is tedious.
Regards,
Amit Saxena
[1]: https://answers.splunk.com/answers/221798/exportimport-splunk-project.html
[2]: https://answers.splunk.com/answers/88107/export-index-data-from-production-splunk-and-import-intotest-instance-of-splunk.html
↧