Getting Data In

Migrating existing indexed data to a cluster environment - Splunk 5

wcushingcandela
New Member

I've read all the splunkbase questions and documentation regarding how non-clustered indexed data is dealt with when moving to a clustered environment. Is it possible to extract the data out of the non-clustered index, with the existing data, and present it to a clustered index as new data?

This way the new data is replicated across all indexers without having to keep a copy of the entire non-clustered index on each indexer.

Thanks.

0 Karma

csharp_splunk
Splunk Employee
Splunk Employee

How long is your data retention? Most customers keep data for 90 days at most for a lot of use cases, and the level of effort to solve the data clustering problem (which has always existed since we just released a clustering solution) isn't worth it when you can just wait over the time period you retain data and eventually the problem will sort itself out. All new data will be replicated. If that's unacceptable, we have internal methods of procedure to force existing data to be replicated out to other indexers, but it would require a professional services engagement to do so.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...