Deployment Architecture

When old indexer servers in an indexer cluster are moved to new servers, what is the best way to move disk or data?

koshyk
Super Champion

Situation: Indexer cluster, dual site, replication factor=2

We have some old indexer servers to be moved to new servers. The disk is going to be the same and reused.

  1. Can we just move the disk to new server if the hostname is mapped to old indexer?
  2. In indexer cluster, there is the GUID of machine in the bucket name. Will this be an issue?
  3. Will there be an issue with replicated buckets (rb) ?
0 Karma
1 Solution

Masa
Splunk Employee
Splunk Employee

In a way, you can do it.

If you're not going to use the old server, I recommend to copy all the $SPLUNK_HOME contents to the new server.
or, try to use the same host name, site and GUID (instance.cfg) for the new instance.

View solution in original post

Masa
Splunk Employee
Splunk Employee

In a way, you can do it.

If you're not going to use the old server, I recommend to copy all the $SPLUNK_HOME contents to the new server.
or, try to use the same host name, site and GUID (instance.cfg) for the new instance.

koshyk
Super Champion

"instance.cfg" just didn't work as it had lot of issues.
Atlast went with whole copy of $SPLUNK_HOME which went smooth

0 Karma

koshyk
Super Champion

thanks @Masa for pointing out "instance.cfg".
Will a direct copy of "$SPLUNK_HOME" work? or do i need to clear _raft etc?

0 Karma

aaraneta_splunk
Splunk Employee
Splunk Employee

@koshyk - Did Masa's answer help to provide a solution to your question? If yes, please don't forget to click "Accept" below the answer to resolve this post. Thanks!

0 Karma

Masa
Splunk Employee
Splunk Employee

A direct copy of "$SPLUNK_HOME" should work. I still recommend you to test it in a small test environment.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...