Getting Data In

How to forward already indexed data after converting Splunk into a Forwarder

wbordeau
Explorer

I configured my original Splunk installation to forward data to newer, faster hardware but noticed only data after this change has been forwarded. How do I move over all the other data that has been indexed on the original server up to that point?

Also, how do I configure the original Splunk installation to be a regular forwarder? I want the Splunk receiver to handle indexing and searching only.

Tags (2)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi wbordeau

maybe this helps:

http://www.splunk.com/wiki/Deploy:Migrating_a_Splunk_Install
http://www.splunk.com/base/Documentation/latest/Admin/Moveanindex

regards

addition: your old indexer will only forward new data, the old already indexed data will stay.

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...