Getting Data In

Multiple Splunk indexer with same $SPLUNK_DB location

sujoybose77
Explorer

Hi,
I have $SPLUNK_DB set up in a NAS storage. But the indexer is installed in a VM (say VM1) running on splunk version 6.3.4.
Now I want to migrate the indexers to another VM (VM2) with newer splunk version 6.6.12 keeping the same NAS location as $SPLUNK_DB.
Is it possible? I have heard that no two indexer will see each other's indexed files. Is that true?
In that case what approach I can take to migrate my indexer?

0 Karma

woodcock
Esteemed Legend

Why would you do this? Working with VMs makes this kind of thing easy so you should not need 2 indexers at the same time. Your forwarders can buffer events for the short time that it would take to upgrade your VM/splunk and have it come back up. You are overcomplicating your situation.

0 Karma

sujoybose77
Explorer

Woodcock, We have organization limitations on VM storage that's not enough to hold large amount of indexed data

0 Karma

woodcock
Esteemed Legend

You need to clarify your question. It doesn't make sense to me.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...