Installation

Migrating data to SplunkStore

jking81
Explorer

We're retiring our internally hosted Splunk environment and moving the data into an EC2 instance on AWS. It seems like our best solution is to use SmartStore and I'm trying to determine the best way to migrate our data.

  1. We're moving multiple TB of logs
  2. Once that data is in S3, we won't be adding any new logs to Splunk.
  3. We would like the old data searchable.
  4. We will be reducing our Indexer count for 7 down to 2 as this environment will be minimally accessed.

I believe the best solution is to enable SmartStore on our servers and once the data is transferred to S3, create the new indexers and decommission our old environment. Am I missing something with this plan?

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...

Deep Dive: Optimizing Telemetry Pipelines in Splunk Observability Cloud

In this session, we will peel back the layers of Splunk Observability Cloud’s cost-optimization features. ...