<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Data sending in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Data-sending/m-p/747783#M14397</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274807"&gt;@SN1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not 100% sure if I'm following what your requirements are here, which scenario is this?&lt;/P&gt;&lt;P&gt;1) You want to move existing stored data from your indexer to be stored on your SH to turn it into an All-In-One?&lt;/P&gt;&lt;P&gt;2) Configure the indexer to forward new data as it arrives to the SH?&lt;/P&gt;&lt;P&gt;3) Move existing data *and* configure forwarding of new data to the SH?&lt;/P&gt;&lt;P&gt;Please let me know so we can provide a better response.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jun 2025 06:24:25 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-06-11T06:24:25Z</dc:date>
    <item>
      <title>Data sending</title>
      <link>https://community.splunk.com/t5/Installation/Data-sending/m-p/747780#M14394</link>
      <description>&lt;P&gt;we have a index where the data is currently being stored and indexed on the indexer . Now i am making Search head standalone and i want to send the data from indexer to sh . How to do it.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 06:09:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Data-sending/m-p/747780#M14394</guid>
      <dc:creator>SN1</dc:creator>
      <dc:date>2025-06-11T06:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: Data sending</title>
      <link>https://community.splunk.com/t5/Installation/Data-sending/m-p/747781#M14395</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274807"&gt;@SN1&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;To clarify your scenario,&lt;BR /&gt;&lt;SPAN&gt;You want Search Head to query the indexer for data as needed or having data on the Search Head for&amp;nbsp; testing/some reason without using the indexer?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 06:17:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Data-sending/m-p/747781#M14395</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-06-11T06:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Data sending</title>
      <link>https://community.splunk.com/t5/Installation/Data-sending/m-p/747782#M14396</link>
      <description>&lt;P&gt;ok let me explain briefly ,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;we are making our search head a standalone . so now i want to send some important data from indexer which is currently being stored and onboarded from the source to Search head . Is this clear.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 06:21:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Data-sending/m-p/747782#M14396</guid>
      <dc:creator>SN1</dc:creator>
      <dc:date>2025-06-11T06:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: Data sending</title>
      <link>https://community.splunk.com/t5/Installation/Data-sending/m-p/747783#M14397</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274807"&gt;@SN1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not 100% sure if I'm following what your requirements are here, which scenario is this?&lt;/P&gt;&lt;P&gt;1) You want to move existing stored data from your indexer to be stored on your SH to turn it into an All-In-One?&lt;/P&gt;&lt;P&gt;2) Configure the indexer to forward new data as it arrives to the SH?&lt;/P&gt;&lt;P&gt;3) Move existing data *and* configure forwarding of new data to the SH?&lt;/P&gt;&lt;P&gt;Please let me know so we can provide a better response.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 06:24:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Data-sending/m-p/747783#M14397</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-11T06:24:25Z</dc:date>
    </item>
    <item>
      <title>Re: Data sending</title>
      <link>https://community.splunk.com/t5/Installation/Data-sending/m-p/747784#M14398</link>
      <description>&lt;P&gt;In the meantime, if you are wanting to move the existing data from your indexer to your SH then&amp;nbsp;stop Splunk on both servers and copy the full directory structure for each index (usually under $SPLUNK_DB, by default $SPLUNK_HOME/var/lib/splunk/&amp;lt;indexname&amp;gt;) from the old indexer to the new server. After copying, ensure Splunk points to the correct path for these indexes in indexes.conf on the new instance.&lt;/P&gt;&lt;P&gt;Restart Splunk on the new instance for the data to be available.&lt;/P&gt;&lt;P&gt;If there are no existing indexes with the same name on the new instance, you can simply copy the directories.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both source and destination should use the same OS and compatible Splunk versions and don't copy buckets from newer Splunk versions to much older versions.&lt;/P&gt;&lt;P&gt;If your SH is still setup to search your IDX then you should probably disconnect it at this point as your may see duplicate data.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 06:30:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Data-sending/m-p/747784#M14398</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-11T06:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Data sending</title>
      <link>https://community.splunk.com/t5/Installation/Data-sending/m-p/747785#M14399</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274807"&gt;@SN1&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;If you must move indexed data from the indexer to the Search Head, you can copy the data files,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Stop Splunk on both the indexer and the Search Head.&lt;/P&gt;&lt;P&gt;Copy the index data directories from the indexer to the Search Head:&lt;/P&gt;&lt;P&gt;Example: Copy $SPLUNK_HOME/var/lib/splunk/&amp;lt;index_name&amp;gt; from the indexer to the same path on the Search Head.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Ensure&lt;/STRONG&gt; file ownership,permissions,storage size,os and splunk versions are correct on the Search Head.&lt;/P&gt;&lt;P&gt;Also make sure you have configuration for the indexes.conf for the indexes you have.&lt;/P&gt;&lt;P&gt;Start Splunk on the Search Head.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a kudos/Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 06:37:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Data-sending/m-p/747785#M14399</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-06-11T06:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: Data sending</title>
      <link>https://community.splunk.com/t5/Installation/Data-sending/m-p/747786#M14400</link>
      <description>&lt;P&gt;also in future we would be &lt;SPAN&gt;Decommissioning the indexer after i have send the data to sh and then i will be sending data directly to sh&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 06:41:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Data-sending/m-p/747786#M14400</guid>
      <dc:creator>SN1</dc:creator>
      <dc:date>2025-06-11T06:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: Data sending</title>
      <link>https://community.splunk.com/t5/Installation/Data-sending/m-p/747788#M14401</link>
      <description>&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;P&gt;also in future we would be &lt;SPAN&gt;Decommissioning the indexer after i have send the data to sh and then i will be sending data directly to sh&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 11 Jun 2025 06:50:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Data-sending/m-p/747788#M14401</guid>
      <dc:creator>SN1</dc:creator>
      <dc:date>2025-06-11T06:50:35Z</dc:date>
    </item>
  </channel>
</rss>

