Deployment Architecture







0 Karma

Ultra Champion

Google Translate:

In the cluster configuration of Splunk
Enterprise, the data captured after
clustering is replicated, but it is
not replicated to index data already
running standalone. Is there a way to
incorporate existing index data into
the cluster configuration?

I think that you should tell me if you
know something by assuming that you
will manually work such as migrating
data (bucket).

Splunk version is 6.4.4.

Above, thank you.

If I understand the question, you are asking how to move data on a standalone indexer into an existing(?) cluster.

Data indexed on a standalone indexer will be marked as a legacy bucket, and will not be replicated if you enable indexer clustering - only data indexed after the cluster was built benefit from replication.

If you need to move this data from a standalone you are deprovisioning, it would be worth contacting support to see if they can assist.

If my comment helps, please give it a thumbs up!
0 Karma

Ultra Champion

Hello - If my answer or comments helped you, please accept the answer and upvote. This helps others know that you found a solution, and how it was fixed.

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...