Deployment Architecture

How to forward indexed data to another splunk indexer cluster ?

mibrahim8
Explorer

We have a Indexer Cluster And Search Head Cluster. We need to send all data in a standalone Splunk instance to the indexer cluster without merging this instance in the indexer cluster.

0 Karma

robgora_deloitt
Path Finder

Are you trying to decommission the standalone? Could you allow the data to be aged off gracefully without adding new data to the standalone? If so, you could just add the standalone as a search peer and let the retention period expire. This way, you are not having to move the data over.

Also if you migrate the buckets over by copying all of them, I am not sure they would replicate to the other indexers in the cluster.

0 Karma

deepashri_123
Motivator

Hey@mibrahim8,

Please refer this link below:
http://docs.splunk.com/Documentation/Splunk/7.0.3/Indexer/Moveanindex

Let me know if this helps!!

0 Karma

mibrahim8
Explorer

The Stand alone splunk instance is totally separated from the indexer cluster. So, the exactly needed to migrate the indexed data in this separated splunk standalone instance to the indexer cluster. But the topic mentioned in the Doc.s is to change the directory of the indexed data in the same indexer.

deepashri_123
Motivator

You can move the buckets in the specific index to one of the indexers in cluster in the same index path .
Make sure the indexer in cluster is stopped before moving this data and once the indexer is started the data will be searchable and also the replication will be taken care-of.

0 Karma

kentaage
New Member

I'm not 100% sure, but I don't think the data will be replicated before the buckets has the GUID from the peer in the cluster that now has the data. http://docs.splunk.com/Documentation/Splunk/7.0.3/Indexer/HowSplunkstoresindexes#Bucket_names

0 Karma

splunker12er
Motivator
0 Karma
Get Updates on the Splunk Community!

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more with ITSI’s ...

Accelerate Service Onboarding, Decomposition, Troubleshooting - and more! Faster Time to ValueManaging and ...

New Release | Splunk Enterprise 9.3

Hi Splunky people! We are excited to share the newest updates in Splunk Enterprise 9.3!Admins and Analyst can ...

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...