Deployment Architecture

Copied defaultdb to another server and now cannot access events

mship
Path Finder

Running Splunk 5.0.1 on windows 2008R2. I had to move my index to another server...followed the steps perfectly...rolled hot to warm....copied $SPLUNK_home...\defaltdb to same location on new server...started splunk. All looks good but for example on the summary page HostA has 6500 events and when I search all time for HOSTA I on receive 10 events (from today)?? Why can't I access the events copied over? It's not a permissions issue?? Another thing I on a workgroup enviornment not an active directory domain. The user that I am logged in on is the same username on each system.

Tags (1)
0 Karma

mship
Path Finder

Thanks for the input Drainy...your troubleshooting lead to me finding the issue...see http://splunk-base.splunk.com/answers/77976/process-to-copy-index-from-one-windows-server-to-another...

0 Karma

Drainy
Champion

After starting Splunk are the index sizes the same on both servers?
Is it just defaultdb you transferred over?

Also, have you checked the permissions on the buckets you've moved over? Just to be sure Splunk can read all of them.

Final check might be to run FSCK on them to check their integrity;
http://docs.splunk.com/Documentation/Splunk/5.0.2/Indexer/HowSplunkstoresindexes#Troubleshoot_your_b...

(Also, if an old answer doesn't help it might be worthwill posting a comment instead of voting it down when it answers the original question 🙂 )

mship
Path Finder

It was just the defaultdb that I transfered and all of the permissions are good. I have not run an FSCK yet.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...