Getting Data In

Migrating existing indexed data to a cluster environment - Splunk 5

wcushingcandela
New Member

I've read all the splunkbase questions and documentation regarding how non-clustered indexed data is dealt with when moving to a clustered environment. Is it possible to extract the data out of the non-clustered index, with the existing data, and present it to a clustered index as new data?

This way the new data is replicated across all indexers without having to keep a copy of the entire non-clustered index on each indexer.

Thanks.

0 Karma

csharp_splunk
Splunk Employee
Splunk Employee

How long is your data retention? Most customers keep data for 90 days at most for a lot of use cases, and the level of effort to solve the data clustering problem (which has always existed since we just released a clustering solution) isn't worth it when you can just wait over the time period you retain data and eventually the problem will sort itself out. All new data will be replicated. If that's unacceptable, we have internal methods of procedure to force existing data to be replicated out to other indexers, but it would require a professional services engagement to do so.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...