Getting Data In

How to condense data from 4 non-clustered indexers that are set up as VMs into a single dedicated hardware server?

john_miller1
Explorer

I currently have 4 indexers setup as VMs. Each indexer has dedicated LUNs for their data. I'm trying to find a way to preserve data while condensing the 4 virtual indexers into a single dedicated hardware host. Any fairly straight forward method to do so or is it a situation where I am better off keeping them for historical purposes for a year (PCI data) and have all of my forwarders just start writing to the new indexer?

Tags (2)
0 Karma
1 Solution

effem
Communicator

A way to do so, would be, to roll everything over to archive (frozen) and reindex it on the new host.

See http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Automatearchiving
and: http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Restorearchiveddata

This is not tied to the origin indexer. So there will be no problem with bucket-id's and stuff.
The only problem is the time you need, to roll it over and back again.

View solution in original post

effem
Communicator

A way to do so, would be, to roll everything over to archive (frozen) and reindex it on the new host.

See http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Automatearchiving
and: http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Restorearchiveddata

This is not tied to the origin indexer. So there will be no problem with bucket-id's and stuff.
The only problem is the time you need, to roll it over and back again.

john_miller1
Explorer

Outstanding, thanks for info! I'll give this a shot!

0 Karma

effem
Communicator

Don't forget to add a partition to your "frozen"-directory e.g. giving it a folder in your indexes.conf.

If you miss that, your data will be deleted!

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...