<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Consolidating Splunk servers in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191981#M7188</link>
    <description>&lt;P&gt;Awesome. I've already moved searches over and have been using them on Splunk 1 so everything should continue to work as expected. I plan on consolidating in the next day or two, so I'll report back. Thanks again!&lt;/P&gt;</description>
    <pubDate>Mon, 30 Dec 2013 15:45:56 GMT</pubDate>
    <dc:creator>sc0tt</dc:creator>
    <dc:date>2013-12-30T15:45:56Z</dc:date>
    <item>
      <title>Consolidating Splunk servers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191977#M7184</link>
      <description>&lt;P&gt;We currently have Splunk running on two separate servers in a distributed search environment. However, we need to eliminate the second server and consolidate Splunk to a single instance. I came across a similar question (&lt;A href="http://answers.splunk.com/answers/10184/consolidate-databases-from-multiple-splunk-instances/" title="Consolidate Databases from multiple splunk instances"&gt;Consolidate Databases from multiple splunk instances&lt;/A&gt;). &lt;/P&gt;

&lt;P&gt;Is this process still the same for Splunk 6? Are there any potential issues with doing this? Existing searches and reports will still need to access the historical data from Splunk 2.&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2013 14:59:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191977#M7184</guid>
      <dc:creator>sc0tt</dc:creator>
      <dc:date>2013-12-30T14:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Consolidating Splunk servers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191978#M7185</link>
      <description>&lt;P&gt;You might want to look at using Shuttl to move the data from the second server to the first.&lt;/P&gt;

&lt;P&gt;Shuttl:&lt;BR /&gt;
&lt;A href="http://apps.splunk.com/app/1195/"&gt;http://apps.splunk.com/app/1195/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2013 15:05:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191978#M7185</guid>
      <dc:creator>treinke</dc:creator>
      <dc:date>2013-12-30T15:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Consolidating Splunk servers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191979#M7186</link>
      <description>&lt;P&gt;Thanks. My understanding is that the only thing I would need to do is to redirect traffic to Splunk 1 and then use Shuttl to manage the moving of data from Splunk 2 to Splunk 1. Is this correct? If so, this seems like it may be simpler than I initially imagined.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2013 15:31:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191979#M7186</guid>
      <dc:creator>sc0tt</dc:creator>
      <dc:date>2013-12-30T15:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Consolidating Splunk servers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191980#M7187</link>
      <description>&lt;P&gt;Correct.  If you have any saved searches on server you would need to move them over also, but Shuttl really makes the process easier.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2013 15:36:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191980#M7187</guid>
      <dc:creator>treinke</dc:creator>
      <dc:date>2013-12-30T15:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: Consolidating Splunk servers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191981#M7188</link>
      <description>&lt;P&gt;Awesome. I've already moved searches over and have been using them on Splunk 1 so everything should continue to work as expected. I plan on consolidating in the next day or two, so I'll report back. Thanks again!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2013 15:45:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191981#M7188</guid>
      <dc:creator>sc0tt</dc:creator>
      <dc:date>2013-12-30T15:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: Consolidating Splunk servers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191982#M7189</link>
      <description>&lt;P&gt;One more question - do you know if Shuttl is compatible with Splunk 6? On the app page it only shows 5.0 and 4.3.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Dec 2013 15:48:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191982#M7189</guid>
      <dc:creator>sc0tt</dc:creator>
      <dc:date>2013-12-30T15:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: Consolidating Splunk servers</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191983#M7190</link>
      <description>&lt;P&gt;FYI - After following up with Splunk it appears that the most recent version of Shuttl is not compatible with Splunk 6. However, manually copying the bucket folders should be simple enough.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jan 2014 09:52:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Consolidating-Splunk-servers/m-p/191983#M7190</guid>
      <dc:creator>sc0tt</dc:creator>
      <dc:date>2014-01-05T09:52:09Z</dc:date>
    </item>
  </channel>
</rss>

