<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Non Clustered buckets in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Non-Clustered-buckets/m-p/402647#M170927</link>
    <description>&lt;P&gt;we was a non clustered environment later we moved to clustered environment. But is my search head will still be able to search the data from non-clustered buckets ?&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jun 2019 22:41:25 GMT</pubDate>
    <dc:creator>ram254481493</dc:creator>
    <dc:date>2019-06-06T22:41:25Z</dc:date>
    <item>
      <title>Splunk Non Clustered buckets</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Non-Clustered-buckets/m-p/402645#M170925</link>
      <description>&lt;P&gt;Hi , we migrated an indexer from non clustered to a clustered environment , i know the naming convention for clustered and non clustered buckets are different. So is the data which lies in non clustered buckets is still be searchable on my clustered environment. If so how ?&lt;/P&gt;

&lt;P&gt;2) i saw in my cold directory i have an additional backup folder created where all of my indexes backups stored , it not defined in indexes.conf and not sure who created ? is it created by default ?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2019 20:29:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Non-Clustered-buckets/m-p/402645#M170925</guid>
      <dc:creator>ram254481493</dc:creator>
      <dc:date>2019-06-03T20:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Non Clustered buckets</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Non-Clustered-buckets/m-p/402646#M170926</link>
      <description>&lt;P&gt;Are you moving to a site aware cluster, or a non site aware cluster. The procedure for getting searchable and properly replicated data from non clustered buckets to clustered buckets is different between the two. If moving to a non site aware cluster, you can do the following:&lt;/P&gt;

&lt;P&gt;Rename buckets in conform to the clustered bucket format. You can avoid bucket clashes by incrementing the bucket number as part of the rename/copy and picking an arbitrarily high bucket number so as to avoid a clash with any existing clustered buckets. I would strongly recommend that you go to a multisite cluster though, as it makes future growth of your cluster easier to manage and administer.&lt;/P&gt;

&lt;P&gt;Another option available to you is to create a new cluster of indexers altogether, and then to have your search heads search across both the clustered indexers, and your older all in one instance until such time as the data in the all in one instance ages out (i.e. no new data goes into it from the time the indexer cluster is stood up) and then you can decommission it. &lt;/P&gt;</description>
      <pubDate>Mon, 03 Jun 2019 21:55:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Non-Clustered-buckets/m-p/402646#M170926</guid>
      <dc:creator>martynoconnor</dc:creator>
      <dc:date>2019-06-03T21:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Non Clustered buckets</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Non-Clustered-buckets/m-p/402647#M170927</link>
      <description>&lt;P&gt;we was a non clustered environment later we moved to clustered environment. But is my search head will still be able to search the data from non-clustered buckets ?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 22:41:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Non-Clustered-buckets/m-p/402647#M170927</guid>
      <dc:creator>ram254481493</dc:creator>
      <dc:date>2019-06-06T22:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Non Clustered buckets</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Splunk-Non-Clustered-buckets/m-p/402648#M170928</link>
      <description>&lt;P&gt;Hi there, yes, if you simply enable clustering on what was once a non-clustered indexer then all future buckets will be clustered and replicated, but you will run the risk of data loss on pre-cluster buckets as they will not replicate unless you trick the indexers into thinking they are clustered buckets using the bucket renaming detailed above. If that risk is acceptable, the move is quite simple. However, I would strongly recommend you move to a multisite cluster rather than a non site-aware cluster. It will save so much pain in the long run and it gives you better control over distribution of replicated copies of data for DR purposes.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 18:49:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Splunk-Non-Clustered-buckets/m-p/402648#M170928</guid>
      <dc:creator>martynoconnor</dc:creator>
      <dc:date>2019-06-07T18:49:35Z</dc:date>
    </item>
  </channel>
</rss>

