Getting Data In

How do we migrate indexed data from a 3-site cluster to a 2-site cluster?

tgadbois
New Member

We have a 3-site cluster with one site being primary, the other two being for HA/DR. So all primary data goes to site 1, and one copy of each bucket is replicated to sites 2 and 3.

We're migrating to new hardware, and keeping the old indexers online/letting existing data age out isn't an option. In our future configuration, we want a 2-site cluster with both sites "active" (i.e., receiving primary data and replicating to the other site).

What's the best way to go about this? Should we just move the primary buckets from site 1 into the new cluster and let Splunk replicate across the two sites? Should we decommission one of our existing sites, so there's site parity between the two environments before migrating data?

Tags (1)
0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

hello,

you cant remove a site like this because there will be buckets from the removed site that are replicated to the site you keep -> splunk will (really) complain about this.

but since 7.0, you can decommission a site with this method by aliasing the decommissioned site :
decommission a site

then depending on the target, you could use the offline indexer procedure from doc

sloshburch
Splunk Employee
Splunk Employee

That link seems perfecto!

I might be oversimplifiing, but before an article like that exists, I would have assumed this was just a matter of adding the new site and manipulating the Master RF and SF to force it to push copies to the future state hardware (every that's not being removed) and then you'll be safe to decommission and update the Master config accordingly. That's where the sitex params (not origin) come in handy.

That might be just what the docs say but figured I'd talk without thinking...;)

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...