Getting Data In

Move bucket between 2 different Splunks

hketer
Path Finder

Hi Everyone!

I've tested the transferring buckets between 2 different Splunks, both of them are Win.
Transferred .bucketManifest file and hot_v1_0 folder from the old Splunk to the New.
After restart I still cant see the data.
I also tried to transfer the the db folder .

What am I missing?
Please assist.

Thank you!! 🙂

Tags (1)
0 Karma

schose
Builder

Hi,

you can just copy one index to another host (as far as there are single-instances) - there are no issues with that. just make sure your settings for indexes.conf are the same and file permissions are set accordingly.

This also works for clustered enviorments with a little more efford.

Regards,

Andreas

0 Karma

hketer
Path Finder

Thank you for answering!
I did all of these and yet I cant search the data.

0 Karma

hketer
Path Finder

Splunk version - Win 7.3

0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...