Getting Data In

How do you transfer indexes stored in a search head to other search peers?

charleschen8
Engager

We have a Splunk environment with 1 search head, multiple indexers, and search peers. Currently search head stores a huge amount of Indexed data. Our requirement is to migrate Search head and Indexers/search peers to new servers. While doing this , we want to reduce volume of Indexed data in new search head, so we are thinking of distributing indexed data from search head to other peers.

All the servers are Windows based and version of Splunk is 7.0

Please let us know what is the right way of doing it.

Along with it , can you please also share instructions to be followed while migrating Indexers/Search peers and License server from one server to another ?

0 Karma

iandrews_splunk
Splunk Employee
Splunk Employee

Charles,

Moving indexed data can be as simple as stopping splunk, moving the index directories, then starting it back up. However, there are some issues that can arise, based on your setup. I suggest you read https://wiki.splunk.com/Community:MoveIndexes and http://docs.splunk.com/Documentation/Splunk/7.0.0/Indexer/Moveanindex thoroughly, have backups, and test it beforehand.

As for license masters, just upload your license to a new master and point your new servers to it. License masters are pretty straight forward.

Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...