<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Move defaultdb to another indexer in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Move-defaultdb-to-another-indexer/m-p/108447#M183452</link>
    <description>&lt;P&gt;I want to move my defaultdb from one indexer to another.  The data will be put in an index called "OLD" on the new indexer and it's really for the purpose of looking up past events indexed.  The indexer where the defaultdb lives right now will be going away.&lt;/P&gt;

&lt;P&gt;How can i roll the default db and copy it to a new indexer?  Also I don't see the default db listed under "Indexes" when I login to splunk and look for it.  &lt;/P&gt;

&lt;P&gt;Isn't the defaultdb where most of your data goes unless you specify otherwise?  I'm a bit confused here...&lt;/P&gt;

&lt;P&gt;My defaultdb has 88g.  My _internal db has 3.2g....&lt;/P&gt;

&lt;P&gt;I tried this command and after putting in my userid and password a bunch of code just flew by on the screen:&lt;/P&gt;

&lt;P&gt;./splunk _internal call /data/indexes/defaultdb/roll-hot-buckets&lt;/P&gt;

&lt;P&gt;Here's an example of the code for summary index:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;entry&amp;gt;
&amp;lt;title&amp;gt;summary&amp;lt;/title&amp;gt;
&amp;lt;id&amp;gt;https://127.0.0.1:8089/servicesNS/nobody/system/data/indexes/summary&amp;lt;/id&amp;gt;
&amp;lt;updated&amp;gt;2012-06-15T20:32:31+00:00&amp;lt;/updated&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/indexes/summary" rel="alternate"/&amp;gt;
&amp;lt;author&amp;gt;
  &amp;lt;name&amp;gt;nobody&amp;lt;/name&amp;gt;
&amp;lt;/author&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/indexes/summary" rel="list"/&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/indexes/summary/_reload" rel="_reload"/&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/indexes/summary" rel="edit"/&amp;gt;
&amp;lt;content type="text/xml"&amp;gt;
  &amp;lt;s:dict&amp;gt;
    &amp;lt;s:key name="assureUTF8"&amp;gt;0&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="blockSignSize"&amp;gt;0&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="blockSignatureDatabase"&amp;gt;_blocksignature&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="coldPath"&amp;gt;$SPLUNK_DB/summarydb/colddb&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="coldPath_expanded"&amp;gt;/opt/splunk/var/lib/splunk/summarydb/colddb&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="coldToFrozenDir"/&amp;gt;
    &amp;lt;s:key name="coldToFrozenScript"/&amp;gt;
    &amp;lt;s:key name="compressRawdata"&amp;gt;1&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="currentDBSizeMB"&amp;gt;1&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="defaultDatabase"&amp;gt;main&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="eai:acl"&amp;gt;
      &amp;lt;s:dict&amp;gt;
        &amp;lt;s:key name="app"&amp;gt;system&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="can_list"&amp;gt;1&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="can_write"&amp;gt;1&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="modifiable"&amp;gt;0&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="owner"&amp;gt;nobody&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="perms"&amp;gt;
          &amp;lt;s:dict&amp;gt;
            &amp;lt;s:key name="read"&amp;gt;
              &amp;lt;s:list&amp;gt;
                &amp;lt;s:item&amp;gt;*&amp;lt;/s:item&amp;gt;
              &amp;lt;/s:list&amp;gt;
            &amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="write"&amp;gt;
              &amp;lt;s:list&amp;gt;
                &amp;lt;s:item&amp;gt;admin&amp;lt;/s:item&amp;gt;
                &amp;lt;s:item&amp;gt;noc&amp;lt;/s:item&amp;gt;
              &amp;lt;/s:list&amp;gt;
            &amp;lt;/s:key&amp;gt;
          &amp;lt;/s:dict&amp;gt;
        &amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="removable"&amp;gt;0&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="sharing"&amp;gt;system&amp;lt;/s:key&amp;gt;
      &amp;lt;/s:dict&amp;gt;
    &amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="enableOnlineBucketRepair"&amp;gt;1&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="enableRealtimeSearch"&amp;gt;1&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="frozenTimePeriodInSecs"&amp;gt;188697600&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="homePath"&amp;gt;$SPLUNK_DB/summarydb/db&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="homePath_expanded"&amp;gt;/opt/splunk/var/lib/splunk/summarydb/db&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="indexThreads"&amp;gt;auto&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="isInternal"&amp;gt;0&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="lastInitTime"&amp;gt;1339792351.566061&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxBloomBackfillBucketAge"&amp;gt;30d&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxConcurrentOptimizes"&amp;gt;3&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxDataSize"&amp;gt;auto&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxHotBuckets"&amp;gt;3&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxHotIdleSecs"&amp;gt;0&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxHotSpanSecs"&amp;gt;7776000&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxMemMB"&amp;gt;5&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxMetaEntries"&amp;gt;1000000&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxRunningProcessGroups"&amp;gt;20&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxRunningProcessGroupsLowPriority"&amp;gt;1&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxTime"/&amp;gt;
    &amp;lt;s:key name="maxTotalDataSizeMB"&amp;gt;500000&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxWarmDBCount"&amp;gt;300&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="memPoolMB"&amp;gt;auto&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="minRawFileSyncSecs"&amp;gt;disable&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="minTime"/&amp;gt;
    &amp;lt;s:key name="partialServiceMetaPeriod"&amp;gt;0&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="quarantineFutureSecs"&amp;gt;2592000&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="quarantinePastSecs"&amp;gt;77760000&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="rawChunkSizeBytes"&amp;gt;131072&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="rotatePeriodInSecs"&amp;gt;60&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="serviceMetaPeriod"&amp;gt;25&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="suppressBannerList"/&amp;gt;
    &amp;lt;s:key name="sync"&amp;gt;0&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="syncMeta"&amp;gt;1&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="thawedPath"&amp;gt;$SPLUNK_DB/summarydb/thaweddb&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="thawedPath_expanded"&amp;gt;/opt/splunk/var/lib/splunk/summarydb/thaweddb&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="throttleCheckPeriod"&amp;gt;15&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="totalEventCount"&amp;gt;0&amp;lt;/s:key&amp;gt;
  &amp;lt;/s:dict&amp;gt;
&amp;lt;/content&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;BR /&gt;
&lt;/P&gt;

&lt;P&gt;is this normal?  I looked at my defaultdb directory and I still have 2 hot buckets that weren't rolled.  I also looked at the code output from running this command and didn't see anything for defaultdb in there at all.  &lt;/P&gt;</description>
    <pubDate>Wed, 25 Jul 2012 19:50:11 GMT</pubDate>
    <dc:creator>gnovak</dc:creator>
    <dc:date>2012-07-25T19:50:11Z</dc:date>
    <item>
      <title>Move defaultdb to another indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Move-defaultdb-to-another-indexer/m-p/108447#M183452</link>
      <description>&lt;P&gt;I want to move my defaultdb from one indexer to another.  The data will be put in an index called "OLD" on the new indexer and it's really for the purpose of looking up past events indexed.  The indexer where the defaultdb lives right now will be going away.&lt;/P&gt;

&lt;P&gt;How can i roll the default db and copy it to a new indexer?  Also I don't see the default db listed under "Indexes" when I login to splunk and look for it.  &lt;/P&gt;

&lt;P&gt;Isn't the defaultdb where most of your data goes unless you specify otherwise?  I'm a bit confused here...&lt;/P&gt;

&lt;P&gt;My defaultdb has 88g.  My _internal db has 3.2g....&lt;/P&gt;

&lt;P&gt;I tried this command and after putting in my userid and password a bunch of code just flew by on the screen:&lt;/P&gt;

&lt;P&gt;./splunk _internal call /data/indexes/defaultdb/roll-hot-buckets&lt;/P&gt;

&lt;P&gt;Here's an example of the code for summary index:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;entry&amp;gt;
&amp;lt;title&amp;gt;summary&amp;lt;/title&amp;gt;
&amp;lt;id&amp;gt;https://127.0.0.1:8089/servicesNS/nobody/system/data/indexes/summary&amp;lt;/id&amp;gt;
&amp;lt;updated&amp;gt;2012-06-15T20:32:31+00:00&amp;lt;/updated&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/indexes/summary" rel="alternate"/&amp;gt;
&amp;lt;author&amp;gt;
  &amp;lt;name&amp;gt;nobody&amp;lt;/name&amp;gt;
&amp;lt;/author&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/indexes/summary" rel="list"/&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/indexes/summary/_reload" rel="_reload"/&amp;gt;
&amp;lt;link href="/servicesNS/nobody/system/data/indexes/summary" rel="edit"/&amp;gt;
&amp;lt;content type="text/xml"&amp;gt;
  &amp;lt;s:dict&amp;gt;
    &amp;lt;s:key name="assureUTF8"&amp;gt;0&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="blockSignSize"&amp;gt;0&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="blockSignatureDatabase"&amp;gt;_blocksignature&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="coldPath"&amp;gt;$SPLUNK_DB/summarydb/colddb&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="coldPath_expanded"&amp;gt;/opt/splunk/var/lib/splunk/summarydb/colddb&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="coldToFrozenDir"/&amp;gt;
    &amp;lt;s:key name="coldToFrozenScript"/&amp;gt;
    &amp;lt;s:key name="compressRawdata"&amp;gt;1&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="currentDBSizeMB"&amp;gt;1&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="defaultDatabase"&amp;gt;main&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="eai:acl"&amp;gt;
      &amp;lt;s:dict&amp;gt;
        &amp;lt;s:key name="app"&amp;gt;system&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="can_list"&amp;gt;1&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="can_write"&amp;gt;1&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="modifiable"&amp;gt;0&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="owner"&amp;gt;nobody&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="perms"&amp;gt;
          &amp;lt;s:dict&amp;gt;
            &amp;lt;s:key name="read"&amp;gt;
              &amp;lt;s:list&amp;gt;
                &amp;lt;s:item&amp;gt;*&amp;lt;/s:item&amp;gt;
              &amp;lt;/s:list&amp;gt;
            &amp;lt;/s:key&amp;gt;
            &amp;lt;s:key name="write"&amp;gt;
              &amp;lt;s:list&amp;gt;
                &amp;lt;s:item&amp;gt;admin&amp;lt;/s:item&amp;gt;
                &amp;lt;s:item&amp;gt;noc&amp;lt;/s:item&amp;gt;
              &amp;lt;/s:list&amp;gt;
            &amp;lt;/s:key&amp;gt;
          &amp;lt;/s:dict&amp;gt;
        &amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="removable"&amp;gt;0&amp;lt;/s:key&amp;gt;
        &amp;lt;s:key name="sharing"&amp;gt;system&amp;lt;/s:key&amp;gt;
      &amp;lt;/s:dict&amp;gt;
    &amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="enableOnlineBucketRepair"&amp;gt;1&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="enableRealtimeSearch"&amp;gt;1&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="frozenTimePeriodInSecs"&amp;gt;188697600&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="homePath"&amp;gt;$SPLUNK_DB/summarydb/db&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="homePath_expanded"&amp;gt;/opt/splunk/var/lib/splunk/summarydb/db&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="indexThreads"&amp;gt;auto&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="isInternal"&amp;gt;0&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="lastInitTime"&amp;gt;1339792351.566061&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxBloomBackfillBucketAge"&amp;gt;30d&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxConcurrentOptimizes"&amp;gt;3&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxDataSize"&amp;gt;auto&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxHotBuckets"&amp;gt;3&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxHotIdleSecs"&amp;gt;0&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxHotSpanSecs"&amp;gt;7776000&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxMemMB"&amp;gt;5&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxMetaEntries"&amp;gt;1000000&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxRunningProcessGroups"&amp;gt;20&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxRunningProcessGroupsLowPriority"&amp;gt;1&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxTime"/&amp;gt;
    &amp;lt;s:key name="maxTotalDataSizeMB"&amp;gt;500000&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="maxWarmDBCount"&amp;gt;300&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="memPoolMB"&amp;gt;auto&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="minRawFileSyncSecs"&amp;gt;disable&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="minTime"/&amp;gt;
    &amp;lt;s:key name="partialServiceMetaPeriod"&amp;gt;0&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="quarantineFutureSecs"&amp;gt;2592000&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="quarantinePastSecs"&amp;gt;77760000&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="rawChunkSizeBytes"&amp;gt;131072&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="rotatePeriodInSecs"&amp;gt;60&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="serviceMetaPeriod"&amp;gt;25&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="suppressBannerList"/&amp;gt;
    &amp;lt;s:key name="sync"&amp;gt;0&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="syncMeta"&amp;gt;1&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="thawedPath"&amp;gt;$SPLUNK_DB/summarydb/thaweddb&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="thawedPath_expanded"&amp;gt;/opt/splunk/var/lib/splunk/summarydb/thaweddb&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="throttleCheckPeriod"&amp;gt;15&amp;lt;/s:key&amp;gt;
    &amp;lt;s:key name="totalEventCount"&amp;gt;0&amp;lt;/s:key&amp;gt;
  &amp;lt;/s:dict&amp;gt;
&amp;lt;/content&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;BR /&gt;
&lt;/P&gt;

&lt;P&gt;is this normal?  I looked at my defaultdb directory and I still have 2 hot buckets that weren't rolled.  I also looked at the code output from running this command and didn't see anything for defaultdb in there at all.  &lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2012 19:50:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Move-defaultdb-to-another-indexer/m-p/108447#M183452</guid>
      <dc:creator>gnovak</dc:creator>
      <dc:date>2012-07-25T19:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Move defaultdb to another indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Move-defaultdb-to-another-indexer/m-p/108448#M183453</link>
      <description>&lt;P&gt;Ran this:  ./splunk _internal call /data/indexes/main/roll-hot-buckets&lt;/P&gt;

&lt;P&gt;Stopped Splunk.  Looked at defaultdb buckets and it rolled them.  I am not sure why it did not work when specifying just defaultdb.  ?  Nevermind guys...I would say that the command should give you some indication that buckets were rolled.  Just having a script fly by me isn't very reassuring...&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jul 2012 20:49:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Move-defaultdb-to-another-indexer/m-p/108448#M183453</guid>
      <dc:creator>gnovak</dc:creator>
      <dc:date>2012-07-25T20:49:33Z</dc:date>
    </item>
  </channel>
</rss>

