Installation

Migrating data to SplunkStore

jking81
Explorer

We're retiring our internally hosted Splunk environment and moving the data into an EC2 instance on AWS. It seems like our best solution is to use SmartStore and I'm trying to determine the best way to migrate our data.

  1. We're moving multiple TB of logs
  2. Once that data is in S3, we won't be adding any new logs to Splunk.
  3. We would like the old data searchable.
  4. We will be reducing our Indexer count for 7 down to 2 as this environment will be minimally accessed.

I believe the best solution is to enable SmartStore on our servers and once the data is transferred to S3, create the new indexers and decommission our old environment. Am I missing something with this plan?

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...