This message originated from Cribl Community Slack.
Click here to view the original link.
Hi! Im about to migrate some data from an old Splunk solution over to a new one. Not all the data. As I have nightmares about multi-line events being messed up using rsync over ssh and oneshot-commands on Splunk I'm thinking about trying to use Cribl to perform this stunt. Has anyone performed this stunt before and can point me in the right direction? Right now im thinking worker and leader cribl on an old search head, splunk ingest into cribl and output to HEC on the new solution. Any help, experience or pointers would be highly appreciated.
Solved
Cribl Data Migration From Splunk To HEC: Seeking Guidance And Best Practices
Best answer by Kam Amir
I wrote this article that should help with either a self-hosted Splunk or Splunk Cloud : https://knowledge.cribl.io/splunk-44/exporting-splunk-data-self-hosted-and-splunk-cloud-options-2005
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
