Getting Data In

Migrating existing indexed data to a cluster environment - Splunk 5

wcushingcandela
New Member

I've read all the splunkbase questions and documentation regarding how non-clustered indexed data is dealt with when moving to a clustered environment. Is it possible to extract the data out of the non-clustered index, with the existing data, and present it to a clustered index as new data?

This way the new data is replicated across all indexers without having to keep a copy of the entire non-clustered index on each indexer.

Thanks.

0 Karma

csharp_splunk
Splunk Employee
Splunk Employee

How long is your data retention? Most customers keep data for 90 days at most for a lot of use cases, and the level of effort to solve the data clustering problem (which has always existed since we just released a clustering solution) isn't worth it when you can just wait over the time period you retain data and eventually the problem will sort itself out. All new data will be replicated. If that's unacceptable, we have internal methods of procedure to force existing data to be replicated out to other indexers, but it would require a professional services engagement to do so.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...