Getting Data In

Migrating existing indexed data to a cluster environment - Splunk 5

wcushingcandela
New Member

I've read all the splunkbase questions and documentation regarding how non-clustered indexed data is dealt with when moving to a clustered environment. Is it possible to extract the data out of the non-clustered index, with the existing data, and present it to a clustered index as new data?

This way the new data is replicated across all indexers without having to keep a copy of the entire non-clustered index on each indexer.

Thanks.

0 Karma

csharp_splunk
Splunk Employee
Splunk Employee

How long is your data retention? Most customers keep data for 90 days at most for a lot of use cases, and the level of effort to solve the data clustering problem (which has always existed since we just released a clustering solution) isn't worth it when you can just wait over the time period you retain data and eventually the problem will sort itself out. All new data will be replicated. If that's unacceptable, we have internal methods of procedure to force existing data to be replicated out to other indexers, but it would require a professional services engagement to do so.

0 Karma
Get Updates on the Splunk Community!

Meet Duke Cyberwalker | A hero’s journey with Splunk

We like to say, the lightsaber is to Luke as Splunk is to Duke. Curious yet? Then read Eric Fusilero’s latest ...

The Future of Splunk Search is Here - See What’s New!

We’re excited to introduce two powerful new search features, now generally available for Splunk Cloud Platform ...

Splunk is Nurturing Tomorrow’s Cybersecurity Leaders Today

Meet Carol Wright. She leads the Splunk Academic Alliance program at Splunk. The Splunk Academic Alliance ...