Migrating data to SplunkStore


We're retiring our internally hosted Splunk environment and moving the data into an EC2 instance on AWS. It seems like our best solution is to use SmartStore and I'm trying to determine the best way to migrate our data.

  1. We're moving multiple TB of logs
  2. Once that data is in S3, we won't be adding any new logs to Splunk.
  3. We would like the old data searchable.
  4. We will be reducing our Indexer count for 7 down to 2 as this environment will be minimally accessed.

I believe the best solution is to enable SmartStore on our servers and once the data is transferred to S3, create the new indexers and decommission our old environment. Am I missing something with this plan?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...