We have a 3-site cluster with one site being primary, the other two being for HA/DR. So all primary data goes to site 1, and one copy of each bucket is replicated to sites 2 and 3.
We're migrating to new hardware, and keeping the old indexers online/letting existing data age out isn't an option. In our future configuration, we want a 2-site cluster with both sites "active" (i.e., receiving primary data and replicating to the other site).
What's the best way to go about this? Should we just move the primary buckets from site 1 into the new cluster and let Splunk replicate across the two sites? Should we decommission one of our existing sites, so there's site parity between the two environments before migrating data?
hello,
you cant remove a site like this because there will be buckets from the removed site that are replicated to the site you keep -> splunk will (really) complain about this.
but since 7.0, you can decommission a site with this method by aliasing the decommissioned site :
decommission a site
then depending on the target, you could use the offline indexer procedure from doc
That link seems perfecto!
I might be oversimplifiing, but before an article like that exists, I would have assumed this was just a matter of adding the new site and manipulating the Master RF and SF to force it to push copies to the future state hardware (every that's not being removed) and then you'll be safe to decommission and update the Master config accordingly. That's where the sitex params (not origin) come in handy.
That might be just what the docs say but figured I'd talk without thinking...;)