I have a plan to migrate data from a single splunk indexer to two separate indexers, reconfiguring the production system from Solaris to RedHat in the process. I've done some testing and it looks like this will work, but need a sanity check. If there are flaws in what I'm proposing let me know... Thanks.
Splunk indexer / web
5TB SAN partition
24 GB RAM
single index (main/defaultdb)
Solaris 10 / Intel x64
Bring up second Splunk Indexer
3TB SAN partition mounted at /opt/splunk
3TB SAN partition mounted at /opt/splunktmp
RedHat 6 Enterprise, x64
create "migrate" index in default location, "migratetmp" index in /opt/splunktmp/var/lib/splunk/
copy db_* directories in existing defaultdb ending in an odd number to migrate/colddb, even numbers to migratetmp/colddb:
Thanks for the confirmation... I had already read the documentation and ran some tests on my own, so I was pretty confident already. My constraint in my situation is the limitation of the two servers. The current production system is going to be refreshed and changed from solaris to redhat, so I don't have the luxury of simply having two servers to move to right off.