How to forward already indexed data after converting Splunk into a Forwarder


I configured my original Splunk installation to forward data to newer, faster hardware but noticed only data after this change has been forwarded. How do I move over all the other data that has been indexed on the original server up to that point?

Also, how do I configure the original Splunk installation to be a regular forwarder? I want the Splunk receiver to handle indexing and searching only.

Hi wbordeau

maybe this helps:


addition: your old indexer will only forward new data, the old already indexed data will stay.

