<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrating from Windows to Linux in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Migrating-from-Windows-to-Linux/m-p/104448#M183176</link>
    <description>&lt;P&gt;If you recreate the indexes locations on the new indexers, you can simply copy the old buckets in the correct folders. (and even spread them over several indexers)&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;example : for the main index the buckets are the subfoldersin $SPLUNK_HOME/var/lib/splunk/defaultdb/db&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;and if you already have existing buckets in the destination, make sure to avoid bucket id duplicates (you can increment them manually)&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;example : in db_1345573209_1345573209_10 the bucket_id is 10, in hot_v1_5 the bucket_id is 5&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;in case of bucket_id collision, here is the behavior : &lt;A href="http://splunk-base.splunk.com/answers/30986/why-is-my-index-disabled" target="_blank"&gt;http://splunk-base.splunk.com/answers/30986/why-is-my-index-disabled&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 12:42:31 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2020-09-28T12:42:31Z</dc:date>
    <item>
      <title>Migrating from Windows to Linux</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Migrating-from-Windows-to-Linux/m-p/104445#M183173</link>
      <description>&lt;P&gt;Hello Splunkers,&lt;BR /&gt;
(1st post)&lt;BR /&gt;
I'm closing down one a Splunk 'test' instance we have on a Windows virtual machine and bringing up a distributed Linux hardware environment w/ 3 Indexers and a single search head. I'm wondering if it would be best to try and migrate/import the data from the VM to one of the Linux Indexers or if it would make more sense to turn the VM into a search peer for the search head? The new Indexers have no data on them as of yet.&lt;BR /&gt;
Any thoughts?&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Lindsay&lt;/P&gt;</description>
      <pubDate>Fri, 26 Oct 2012 21:48:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Migrating-from-Windows-to-Linux/m-p/104445#M183173</guid>
      <dc:creator>lbogle</dc:creator>
      <dc:date>2012-10-26T21:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from Windows to Linux</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Migrating-from-Windows-to-Linux/m-p/104446#M183174</link>
      <description>&lt;P&gt;Long term having to maintain the single windows instance on VM just to keep alive the amount of data collected during the testing phase doesn't seem to make so much sense. I would recommend migrating the data into the new architecture to simplify your deployment. Hope that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2012 15:48:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Migrating-from-Windows-to-Linux/m-p/104446#M183174</guid>
      <dc:creator>pwattssplunk</dc:creator>
      <dc:date>2012-10-29T15:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from Windows to Linux</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Migrating-from-Windows-to-Linux/m-p/104447#M183175</link>
      <description>&lt;P&gt;I agreee, but how important is the data on your Windows server?  I would concider dumping it or moving the indices over.  If you have access to the orginal log data, just reindex it so that its distruted.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2012 16:01:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Migrating-from-Windows-to-Linux/m-p/104447#M183175</guid>
      <dc:creator>bmacias84</dc:creator>
      <dc:date>2012-10-29T16:01:14Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from Windows to Linux</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Migrating-from-Windows-to-Linux/m-p/104448#M183176</link>
      <description>&lt;P&gt;If you recreate the indexes locations on the new indexers, you can simply copy the old buckets in the correct folders. (and even spread them over several indexers)&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;example : for the main index the buckets are the subfoldersin $SPLUNK_HOME/var/lib/splunk/defaultdb/db&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;and if you already have existing buckets in the destination, make sure to avoid bucket id duplicates (you can increment them manually)&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;example : in db_1345573209_1345573209_10 the bucket_id is 10, in hot_v1_5 the bucket_id is 5&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;in case of bucket_id collision, here is the behavior : &lt;A href="http://splunk-base.splunk.com/answers/30986/why-is-my-index-disabled" target="_blank"&gt;http://splunk-base.splunk.com/answers/30986/why-is-my-index-disabled&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:42:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Migrating-from-Windows-to-Linux/m-p/104448#M183176</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2020-09-28T12:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating from Windows to Linux</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Migrating-from-Windows-to-Linux/m-p/104449#M183177</link>
      <description>&lt;P&gt;Thank you for the input everyone. I appreciate it!&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2012 16:04:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Migrating-from-Windows-to-Linux/m-p/104449#M183177</guid>
      <dc:creator>lbogle</dc:creator>
      <dc:date>2012-10-30T16:04:51Z</dc:date>
    </item>
  </channel>
</rss>

