Deployment Architecture

Copied defaultdb to another server and now cannot access events

mship
Path Finder

Running Splunk 5.0.1 on windows 2008R2. I had to move my index to another server...followed the steps perfectly...rolled hot to warm....copied $SPLUNK_home...\defaltdb to same location on new server...started splunk. All looks good but for example on the summary page HostA has 6500 events and when I search all time for HOSTA I on receive 10 events (from today)?? Why can't I access the events copied over? It's not a permissions issue?? Another thing I on a workgroup enviornment not an active directory domain. The user that I am logged in on is the same username on each system.

Tags (1)
0 Karma

mship
Path Finder

Thanks for the input Drainy...your troubleshooting lead to me finding the issue...see http://splunk-base.splunk.com/answers/77976/process-to-copy-index-from-one-windows-server-to-another...

0 Karma

Drainy
Champion

After starting Splunk are the index sizes the same on both servers?
Is it just defaultdb you transferred over?

Also, have you checked the permissions on the buckets you've moved over? Just to be sure Splunk can read all of them.

Final check might be to run FSCK on them to check their integrity;
http://docs.splunk.com/Documentation/Splunk/5.0.2/Indexer/HowSplunkstoresindexes#Troubleshoot_your_b...

(Also, if an old answer doesn't help it might be worthwill posting a comment instead of voting it down when it answers the original question 🙂 )

mship
Path Finder

It was just the defaultdb that I transfered and all of the permissions are good. I have not run an FSCK yet.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...