Getting Data In

How do you transfer indexes stored in a search head to other search peers?

charleschen8
Engager

We have a Splunk environment with 1 search head, multiple indexers, and search peers. Currently search head stores a huge amount of Indexed data. Our requirement is to migrate Search head and Indexers/search peers to new servers. While doing this , we want to reduce volume of Indexed data in new search head, so we are thinking of distributing indexed data from search head to other peers.

All the servers are Windows based and version of Splunk is 7.0

Please let us know what is the right way of doing it.

Along with it , can you please also share instructions to be followed while migrating Indexers/Search peers and License server from one server to another ?

0 Karma

iandrews_splunk
Splunk Employee
Splunk Employee

Charles,

Moving indexed data can be as simple as stopping splunk, moving the index directories, then starting it back up. However, there are some issues that can arise, based on your setup. I suggest you read https://wiki.splunk.com/Community:MoveIndexes and http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Moveanindex thoroughly, have backups, and test it beforehand.

As for license masters, just upload your license to a new master and point your new servers to it. License masters are pretty straight forward.

Get Updates on the Splunk Community!

Observability Unlocked: Kubernetes Monitoring with Splunk Observability Cloud

  Ready to master Kubernetes and cloud monitoring like the pros?Join Splunk’s Growth Engineering team for an ...

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...