Deployment Architecture

How to forward indexed data to another splunk indexer cluster ?

mibrahim8
Explorer

We have a Indexer Cluster And Search Head Cluster. We need to send all data in a standalone Splunk instance to the indexer cluster without merging this instance in the indexer cluster.

0 Karma

robgora_deloitt
Path Finder

Are you trying to decommission the standalone? Could you allow the data to be aged off gracefully without adding new data to the standalone? If so, you could just add the standalone as a search peer and let the retention period expire. This way, you are not having to move the data over.

Also if you migrate the buckets over by copying all of them, I am not sure they would replicate to the other indexers in the cluster.

0 Karma

deepashri_123
Motivator

Hey@mibrahim8,

Please refer this link below:
http://docs.splunk.com/Documentation/Splunk/7.0.3/Indexer/Moveanindex

Let me know if this helps!!

0 Karma

mibrahim8
Explorer

The Stand alone splunk instance is totally separated from the indexer cluster. So, the exactly needed to migrate the indexed data in this separated splunk standalone instance to the indexer cluster. But the topic mentioned in the Doc.s is to change the directory of the indexed data in the same indexer.

deepashri_123
Motivator

You can move the buckets in the specific index to one of the indexers in cluster in the same index path .
Make sure the indexer in cluster is stopped before moving this data and once the indexer is started the data will be searchable and also the replication will be taken care-of.

0 Karma

kentaage
New Member

I'm not 100% sure, but I don't think the data will be replicated before the buckets has the GUID from the peer in the cluster that now has the data. http://docs.splunk.com/Documentation/Splunk/7.0.3/Indexer/HowSplunkstoresindexes#Bucket_names

0 Karma

splunker12er
Motivator
0 Karma
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...