<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Moved indexed data to different mount - not seeing it in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Moved-indexed-data-to-different-mount-not-seeing-it/m-p/313205#M58702</link>
    <description>&lt;P&gt;Sorry I did mean index.conf, so I want to create a new index and have it index that data?&lt;/P&gt;</description>
    <pubDate>Tue, 21 Feb 2017 16:10:55 GMT</pubDate>
    <dc:creator>omuelle1</dc:creator>
    <dc:date>2017-02-21T16:10:55Z</dc:date>
    <item>
      <title>Moved indexed data to different mount - not seeing it</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Moved-indexed-data-to-different-mount-not-seeing-it/m-p/313203#M58700</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I was running out of space due to large volume of vmware data that we are indexing and I had to move the data to a different mount. I changed in index.conf where the data is being indexed and moved all the db folders (hot,warm,cold) and hot folders to the new mount as well. However when running a search the old data is being ignored, can you somehow force the index to reindex data it already indexed before?&lt;/P&gt;

&lt;P&gt;Oliver&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 15:50:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Moved-indexed-data-to-different-mount-not-seeing-it/m-p/313203#M58700</guid>
      <dc:creator>omuelle1</dc:creator>
      <dc:date>2017-02-21T15:50:09Z</dc:date>
    </item>
    <item>
      <title>Re: Moved indexed data to different mount - not seeing it</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Moved-indexed-data-to-different-mount-not-seeing-it/m-p/313204#M58701</link>
      <description>&lt;P&gt;I am sure that you meant &lt;CODE&gt;indexes.conf&lt;/CODE&gt; but in any case, you clearly did not move the old files to the directory at the new mount point so it created new files.  It can be merged but it is tricky and unsupported.  Your simplest option is to figure out where the disconnect is, rename the old index and create 2 entries in &lt;CODE&gt;indexes.conf&lt;/CODE&gt; and then search against both until the old data ages out and get rid of the old index.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 16:06:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Moved-indexed-data-to-different-mount-not-seeing-it/m-p/313204#M58701</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-02-21T16:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: Moved indexed data to different mount - not seeing it</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Moved-indexed-data-to-different-mount-not-seeing-it/m-p/313205#M58702</link>
      <description>&lt;P&gt;Sorry I did mean index.conf, so I want to create a new index and have it index that data?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 16:10:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Moved-indexed-data-to-different-mount-not-seeing-it/m-p/313205#M58702</guid>
      <dc:creator>omuelle1</dc:creator>
      <dc:date>2017-02-21T16:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Moved indexed data to different mount - not seeing it</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Moved-indexed-data-to-different-mount-not-seeing-it/m-p/313206#M58703</link>
      <description>&lt;P&gt;The correct name is &lt;CODE&gt;indexes.conf&lt;/CODE&gt; so if you used &lt;CODE&gt;index.conf&lt;/CODE&gt; then that is the problem.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 16:14:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Moved-indexed-data-to-different-mount-not-seeing-it/m-p/313206#M58703</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-02-21T16:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Moved indexed data to different mount - not seeing it</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Moved-indexed-data-to-different-mount-not-seeing-it/m-p/313207#M58704</link>
      <description>&lt;P&gt;I know, just made typo..&lt;/P&gt;</description>
      <pubDate>Tue, 21 Feb 2017 16:35:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Moved-indexed-data-to-different-mount-not-seeing-it/m-p/313207#M58704</guid>
      <dc:creator>omuelle1</dc:creator>
      <dc:date>2017-02-21T16:35:12Z</dc:date>
    </item>
  </channel>
</rss>

