I have a 5 node Indexer cluster with version 7.3.1.1. I added configuration to replicate data on indexer cluster but only new data is getting replicated. Old data which is in cluster before I added replication configuration is not replicated.
Is this how it is supposed to be? If not, how can I replicate old data?
Thanks in advance!!
Hi @rteja9,
Splunk replicates only new data it isn't possible to replicate already indexed data, to replicate old data you have to reindex them.
If you don't want to reindex all the old data, the only solution is the one I used last year:
index=my_index OR index=my_index_new
),index=my_index
with eventtype=my_eventtype
,in this way you have a searchable copy of your data in every indexer, and the old data will slowly decrease until the old index will be empty after the retention period.
Ciao.
Giuseppe
Hi @rteja9,
Splunk replicates only new data it isn't possible to replicate already indexed data, to replicate old data you have to reindex them.
If you don't want to reindex all the old data, the only solution is the one I used last year:
index=my_index OR index=my_index_new
),index=my_index
with eventtype=my_eventtype
,in this way you have a searchable copy of your data in every indexer, and the old data will slowly decrease until the old index will be empty after the retention period.
Ciao.
Giuseppe
Thanks for your response. That makes sense.