<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: moving index to one server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/moving-index-to-one-server/m-p/46958#M96729</link>
    <description>&lt;P&gt;This worked. Can you explain why indexes automatically got enabled when it is restarted?&lt;BR /&gt;
Thank You&lt;/P&gt;</description>
    <pubDate>Thu, 30 Aug 2012 17:10:28 GMT</pubDate>
    <dc:creator>gudavasr</dc:creator>
    <dc:date>2012-08-30T17:10:28Z</dc:date>
    <item>
      <title>moving index to one server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/moving-index-to-one-server/m-p/46956#M96727</link>
      <description>&lt;P&gt;I have indexes on two servers and moved index to one server:&lt;BR /&gt;
I followed the followind guidelines:&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/10184/consolidate-databases-from-multiple-splunk-instances" target="_blank"&gt;http://splunk-base.splunk.com/answers/10184/consolidate-databases-from-multiple-splunk-instances&lt;/A&gt; &lt;BR /&gt;
and&lt;BR /&gt;
&lt;A href="http://splunk-base.splunk.com/answers/34811/how-can-i-find-all-duplicate-bucket-ids-that-are-causing-conflicts-in-my-index?page=1#34834" target="_blank"&gt;http://splunk-base.splunk.com/answers/34811/how-can-i-find-all-duplicate-bucket-ids-that-are-causing-conflicts-in-my-index?page=1#34834&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;but I still get this error:&lt;BR /&gt;
IndexProcessor - received eve&lt;BR /&gt;
IndexProcessor - received event for unconfigured/disabled index='_audit' with source='source::audittrail' host='host::wspra99a0546' sourcetype='sourcetype::audittrail' (1 missing total)&lt;/P&gt;

&lt;P&gt;nt for unconfigured/disabled index='_internal' with source='source::/opt/local/qosmont/splunk_search_head_02_sit/var/log/splunk/splunkd.log' host='host::wspra99a0546' sourcetype='sourcetype::splunkd' (2 missing total)&lt;/P&gt;

&lt;P&gt;How can I fix these?&lt;/P&gt;

&lt;P&gt;Thank You.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:21:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/moving-index-to-one-server/m-p/46956#M96727</guid>
      <dc:creator>gudavasr</dc:creator>
      <dc:date>2020-09-28T12:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: moving index to one server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/moving-index-to-one-server/m-p/46957#M96728</link>
      <description>&lt;P&gt;Hi gudavasr&lt;/P&gt;

&lt;P&gt;check if those indexes are disabled:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| rest /services/data/indexes | table title disabled
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;if so you can enable them in 'Manager &amp;gt;&amp;gt; Indexes'&lt;BR /&gt;
probably it is also possible via REST but I haven't checked on that yet &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;cheers,&lt;BR /&gt;
MuS&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2012 07:41:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/moving-index-to-one-server/m-p/46957#M96728</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-08-30T07:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: moving index to one server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/moving-index-to-one-server/m-p/46958#M96729</link>
      <description>&lt;P&gt;This worked. Can you explain why indexes automatically got enabled when it is restarted?&lt;BR /&gt;
Thank You&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2012 17:10:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/moving-index-to-one-server/m-p/46958#M96729</guid>
      <dc:creator>gudavasr</dc:creator>
      <dc:date>2012-08-30T17:10:28Z</dc:date>
    </item>
  </channel>
</rss>

