splunk export



  •      Import or export Splunk global data, user data, or event data into or out
         of your Splunk server.
    
         Use import and export to migrate data from one Splunk installation to
         another.
    
         Syntax:
    
            export [object] [-parameter <value>] ...
    
            import [object] [-parameter <value>] ...
    
         Objects:
    
            (For both)
              userdata       user accounts
    
            (For export only)
              eventdata      exported events indexed as raw log files
    
         Required Parameters:
    
              userdata     dir    specify which directory to import data from
    
              eventdata    index  (default) specify which Splunk index to export 
    events from
                           dir    specify which directory to export data to
    
    
         Optional Parameters:
    
              userdata     NONE
    
              eventdata    host         export events for the specified host
                           source       export events for the specified source
                           sourcetype   export events for the specified sourcetype
                           terms        export events containing the given terms
    
    
         Examples:
    
              ./splunk import userdata -dir /tmp/export.dat
    
              ./splunk export eventdata -index my_apache_data -dir 
    /tmp/apache_raw_404_logs -host localhost -terms "404 html"
    
              ./splunk export eventdata -index main -dir /tmp/events -host www 
    -sourcetype syslog -terms "dhcp OR bind"
    
    
         Type "help [object|topic]" to view help on a specific object or topic.
    
         Complete documentation is available online at: 
    http://docs.splunk.com/Documentation
    

Log in to reply
 

© Lightnetics 2024