<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to migrate all indexed data from an old Splunk instance to a new Splunk environment? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/How-to-migrate-all-indexed-data-from-an-old-Splunk-instance-to-a/m-p/200830#M3198</link>
    <description>&lt;P&gt;Go through it :. &lt;A href="https://wiki.splunk.com/Community:MoveIndexes"&gt;https://wiki.splunk.com/Community:MoveIndexes&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 18 Apr 2020 16:38:43 GMT</pubDate>
    <dc:creator>marisstella</dc:creator>
    <dc:date>2020-04-18T16:38:43Z</dc:date>
    <item>
      <title>How to migrate all indexed data from an old Splunk instance to a new Splunk environment?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-migrate-all-indexed-data-from-an-old-Splunk-instance-to-a/m-p/200825#M3193</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I would like to recover all the data from an old Splunk instance in order to put it in my new Splunk architecture (2 Indexers and a master also used as a search head). My question is: How to do that? I have read that the indexed data is located in the defaultdb directory. Are there any other files I should copy so that the previous data appears on my new Splunk? Do I have to copy these files in both indexers' directories and master directories?&lt;/P&gt;
&lt;P&gt;Thanks you in advance for any advice.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 23:08:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-migrate-all-indexed-data-from-an-old-Splunk-instance-to-a/m-p/200825#M3193</guid>
      <dc:creator>ameslet</dc:creator>
      <dc:date>2020-06-05T23:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to migrate all indexed data from an old Splunk instance to a new Splunk environment?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-migrate-all-indexed-data-from-an-old-Splunk-instance-to-a/m-p/200826#M3194</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.1/Installation/MigrateaSplunkinstance"&gt;Migrate a Splunk Enterprise instance&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;explains the process.&lt;/P&gt;

&lt;P&gt;About the buckets. It says under 'Bucket IDs and potential bucket collision' -&lt;BR /&gt;
-- If you migrate a Splunk Enterprise instance to another Splunk instance that already has existing indexes with identical names, you must make sure that the individual buckets within those indexes have bucket IDs that do not collide. Splunk Enterprise does not start if it encounters indexes with buckets that have colliding bucket IDs. When you copy index data, you might need to rename the copied bucket files to prevent this condition. &lt;/P&gt;

&lt;P&gt;And this bucket transfer is 'legal' - &lt;BR /&gt;
-- If you want to retire a Splunk Enterprise instance and immediately move the data to another instance, you can move individual buckets of an index between hosts, as long as:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;The source and target hosts have the same endianness.&lt;/LI&gt;
&lt;LI&gt;You are not trying to restore a bucket created by a 4.2 or later version of Splunk Enterprise to a version less than 4.2.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 08 Jun 2016 14:16:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-migrate-all-indexed-data-from-an-old-Splunk-instance-to-a/m-p/200826#M3194</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-06-08T14:16:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to migrate all indexed data from an old Splunk instance to a new Splunk environment?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-migrate-all-indexed-data-from-an-old-Splunk-instance-to-a/m-p/200827#M3195</link>
      <description>&lt;P&gt;Thank you for your answer. I have checked the process described on the documentation. I was wondering, as I have to migrate and update a Splunk instance, I won't be able to monitor any devices during the time I stop my old splunk and  launch the new one. Is there a way I can get these data ?&lt;/P&gt;

&lt;P&gt;Thanks for the help&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2016 10:15:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-migrate-all-indexed-data-from-an-old-Splunk-instance-to-a/m-p/200827#M3195</guid>
      <dc:creator>ameslet</dc:creator>
      <dc:date>2016-06-09T10:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to migrate all indexed data from an old Splunk instance to a new Splunk environment?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-migrate-all-indexed-data-from-an-old-Splunk-instance-to-a/m-p/200828#M3196</link>
      <description>&lt;P&gt;Do I have to install the same version than my old Splunk in a first place and then update it ? &lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2016 10:18:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-migrate-all-indexed-data-from-an-old-Splunk-instance-to-a/m-p/200828#M3196</guid>
      <dc:creator>ameslet</dc:creator>
      <dc:date>2016-06-09T10:18:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to migrate all indexed data from an old Splunk instance to a new Splunk environment?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-migrate-all-indexed-data-from-an-old-Splunk-instance-to-a/m-p/200829#M3197</link>
      <description>&lt;P&gt;please can you give straight steps and naming conversion how the buckets indexes from source to target should like like during migration process?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2020 16:53:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-migrate-all-indexed-data-from-an-old-Splunk-instance-to-a/m-p/200829#M3197</guid>
      <dc:creator>rita201</dc:creator>
      <dc:date>2020-02-18T16:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to migrate all indexed data from an old Splunk instance to a new Splunk environment?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-migrate-all-indexed-data-from-an-old-Splunk-instance-to-a/m-p/200830#M3198</link>
      <description>&lt;P&gt;Go through it :. &lt;A href="https://wiki.splunk.com/Community:MoveIndexes"&gt;https://wiki.splunk.com/Community:MoveIndexes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Apr 2020 16:38:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-migrate-all-indexed-data-from-an-old-Splunk-instance-to-a/m-p/200830#M3198</guid>
      <dc:creator>marisstella</dc:creator>
      <dc:date>2020-04-18T16:38:43Z</dc:date>
    </item>
  </channel>
</rss>

