splunk export
-
Import or export Splunk global data, user data, or event data into or out of your Splunk server. Use import and export to migrate data from one Splunk installation to another. Syntax: export [object] [-parameter <value>] ... import [object] [-parameter <value>] ... Objects: (For both) userdata user accounts (For export only) eventdata exported events indexed as raw log files Required Parameters: userdata dir specify which directory to import data from eventdata index (default) specify which Splunk index to export events from dir specify which directory to export data to Optional Parameters: userdata NONE eventdata host export events for the specified host source export events for the specified source sourcetype export events for the specified sourcetype terms export events containing the given terms Examples: ./splunk import userdata -dir /tmp/export.dat ./splunk export eventdata -index my_apache_data -dir /tmp/apache_raw_404_logs -host localhost -terms "404 html" ./splunk export eventdata -index main -dir /tmp/events -host www -sourcetype syslog -terms "dhcp OR bind" Type "help [object|topic]" to view help on a specific object or topic. Complete documentation is available online at: http://docs.splunk.com/Documentation
© Lightnetics 2024