Getting Data In

How to forward already indexed data after converting Splunk into a Forwarder


I configured my original Splunk installation to forward data to newer, faster hardware but noticed only data after this change has been forwarded. How do I move over all the other data that has been indexed on the original server up to that point?

Also, how do I configure the original Splunk installation to be a regular forwarder? I want the Splunk receiver to handle indexing and searching only.

Tags (2)
0 Karma


Hi wbordeau

maybe this helps:


addition: your old indexer will only forward new data, the old already indexed data will stay.

State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!