Getting Data In

How do we migrate indexed data from a 3-site cluster to a 2-site cluster?

tgadbois
New Member

We have a 3-site cluster with one site being primary, the other two being for HA/DR. So all primary data goes to site 1, and one copy of each bucket is replicated to sites 2 and 3.

We're migrating to new hardware, and keeping the old indexers online/letting existing data age out isn't an option. In our future configuration, we want a 2-site cluster with both sites "active" (i.e., receiving primary data and replicating to the other site).

What's the best way to go about this? Should we just move the primary buckets from site 1 into the new cluster and let Splunk replicate across the two sites? Should we decommission one of our existing sites, so there's site parity between the two environments before migrating data?

Tags (1)
0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

hello,

you cant remove a site like this because there will be buckets from the removed site that are replicated to the site you keep -> splunk will (really) complain about this.

but since 7.0, you can decommission a site with this method by aliasing the decommissioned site :
decommission a site

then depending on the target, you could use the offline indexer procedure from doc

sloshburch
Ultra Champion

That link seems perfecto!

I might be oversimplifiing, but before an article like that exists, I would have assumed this was just a matter of adding the new site and manipulating the Master RF and SF to force it to push copies to the future state hardware (every that's not being removed) and then you'll be safe to decommission and update the Master config accordingly. That's where the sitex params (not origin) come in handy.

That might be just what the docs say but figured I'd talk without thinking...;)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...