Deployment Architecture

既存インデックスのクラスタ化について

cipherjake
Explorer

SplunkEnterpriseのクラスタ構成はクラスタ化の後に取込んだデータはレプリケーションされますが、既にスタンドアロンで動作しているインデックスデータに対してはレプリケーションされません。
既存のインデックスデータをクラスタ構成に組み込む方法は存在するのでしょうか?

データ(バケツ)の移行など手動で作業することも想定して何か手法をご存じの方がいらっしゃれば教えて頂ければと思います。

Splunkのバージョンは6.4.4です。

以上、宜しくお願い致します。

0 Karma

nickhills
Ultra Champion

Google Translate:

In the cluster configuration of Splunk
Enterprise, the data captured after
clustering is replicated, but it is
not replicated to index data already
running standalone. Is there a way to
incorporate existing index data into
the cluster configuration?

I think that you should tell me if you
know something by assuming that you
will manually work such as migrating
data (bucket).

Splunk version is 6.4.4.

Above, thank you.

If I understand the question, you are asking how to move data on a standalone indexer into an existing(?) cluster.

Data indexed on a standalone indexer will be marked as a legacy bucket, and will not be replicated if you enable indexer clustering - only data indexed after the cluster was built benefit from replication.

If you need to move this data from a standalone you are deprovisioning, it would be worth contacting support to see if they can assist.

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

Hello - If my answer or comments helped you, please accept the answer and upvote. This helps others know that you found a solution, and how it was fixed.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...