Getting Data In

Migrating existing indexed data to a cluster environment - Splunk 5

wcushingcandela
New Member

I've read all the splunkbase questions and documentation regarding how non-clustered indexed data is dealt with when moving to a clustered environment. Is it possible to extract the data out of the non-clustered index, with the existing data, and present it to a clustered index as new data?

This way the new data is replicated across all indexers without having to keep a copy of the entire non-clustered index on each indexer.

Thanks.

0 Karma

csharp_splunk
Splunk Employee
Splunk Employee

How long is your data retention? Most customers keep data for 90 days at most for a lot of use cases, and the level of effort to solve the data clustering problem (which has always existed since we just released a clustering solution) isn't worth it when you can just wait over the time period you retain data and eventually the problem will sort itself out. All new data will be replicated. If that's unacceptable, we have internal methods of procedure to force existing data to be replicated out to other indexers, but it would require a professional services engagement to do so.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...