Deployment Architecture

How to move an index to new indexer cluster?


I have an Index,

home path= /data/splunk/indexes/home/index_name/db
cold path = /data/splunk/indexes/cold/index_name/db
thawed path= $Splunk_DB/index_name/

I have to move this index to new indexer cluster. Usually in the documentation it is given to move data in Splunk_DB to new location when you want to move indexes. But my data locations are different (not in Splunk_DB). May I know more about what is the procedure? Moreover I see .dat files in $SPLUNK_DB. what is the significance of those files?

Description from other duplicate question:
How to move index to new cluster where data is in one location(/data/splunk/indexes/.../index_name/db) and .dat files and thawed path in other location(/opt/splunk/var/lib/splunk).

0 Karma


Hi TStrauch,
in is described how to move an index from a location to another.

You said that you want to move an index from a non clustered indexer to a cluster, did I correctly undestand?
remember that an indexer cluster replies only the new events, so if you have old events in your index you cannot copy index files in the new location (they aren't replied)!
I had a similar problem and I solved in this way:

  • I stopped Splunk;
  • I created a new index on cluster (using Master Node) with a different name in a different location;
  • I copied the old index files in all the cluster peers;
  • I redirected all the inputs into the new clustered index;
  • I restarted Splunk;
  • I created an eventtype (index=old_index OR index=new_index) and I used it in my searches instead of index=old_index.


0 Karma

Revered Legend

How are you planning to store the data in new cluster, will the homePath/coldPath and thawedPath will be different there as well? Actually in either case,you move data from old homePath/coldPath to new cluster's homePath/coldPath and data from old thawedPath to new cluster's thawedPath.

0 Karma


ok got it. what I should do with the .dat files present in $SPLUNK_DB directory. should I move them as well to the SPLUNK_DB directory in new server

0 Karma

New Member

Hey ankith

How you solved this. We are having similar schenario, need to move the indexed data to new environment.
Please advise.


0 Karma

Revered Legend

I don't think you need that. I believe it just keeps track of next hot bucket id to use.

0 Karma



just give me a response if i understand something wrong.

Your main problem is that you need to change the "Splunk_DB" variable am i right?

To change the "Splunk_DB" variable just du this.

Stop Splunk
Unset the Splunk_DB variable by "unset SPLUNK_DB"
Then go to "$SPLUNK_HOME/etc/splunk_launch.conf" and change the "SPLUNK_DB" variable to the path of your choice.
Start Splunk

I think there should be no problem by migrating your indexes as described in Docs. The described way in Docs should work for this scenario.

For the .dat files im not 100% sure but i think they hold the next bucket_id for the index.

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...