Getting Data In

How do we migrate indexed data from a 3-site cluster to a 2-site cluster?

tgadbois
New Member

We have a 3-site cluster with one site being primary, the other two being for HA/DR. So all primary data goes to site 1, and one copy of each bucket is replicated to sites 2 and 3.

We're migrating to new hardware, and keeping the old indexers online/letting existing data age out isn't an option. In our future configuration, we want a 2-site cluster with both sites "active" (i.e., receiving primary data and replicating to the other site).

What's the best way to go about this? Should we just move the primary buckets from site 1 into the new cluster and let Splunk replicate across the two sites? Should we decommission one of our existing sites, so there's site parity between the two environments before migrating data?

Tags (1)
0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

hello,

you cant remove a site like this because there will be buckets from the removed site that are replicated to the site you keep -> splunk will (really) complain about this.

but since 7.0, you can decommission a site with this method by aliasing the decommissioned site :
decommission a site

then depending on the target, you could use the offline indexer procedure from doc

sloshburch
Splunk Employee
Splunk Employee

That link seems perfecto!

I might be oversimplifiing, but before an article like that exists, I would have assumed this was just a matter of adding the new site and manipulating the Master RF and SF to force it to push copies to the future state hardware (every that's not being removed) and then you'll be safe to decommission and update the Master config accordingly. That's where the sitex params (not origin) come in handy.

That might be just what the docs say but figured I'd talk without thinking...;)

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...