Knowledge Management

moving a summary index

a212830
Champion

Hi,

One of my customers has a summary index running on a POC that they want to move into my production system. The summary index is on a 4.3 system (windows), and the production system is running on 5.01 (linux). Is it possible to move it? Can I also rename it?

Tags (2)
0 Karma

bmacias84
Champion

Yes, Answer is yes to both questions. Move an index is similar to the process of backup and restoring indexes. Regarding renaming an index I have never don't it but hopefully the links will help you. Dont forget to make sure file system permission are set correctly when migrating.

Here are some docs that will help:

Hope this helps or gets you started. Dont forget to accept answers and vote on answers that help.

Cheers,

bmacias84
Champion

I would gzip and rsyn the directors over to the linux server in the appropriate directory. Make sure ur migrated index is set in the indexes.conf.. Set your permissions use cown and chmod. Both servers must gave splunkd stop while doing this. Permissions need to be correct as ntfs perms will not match or carry over.

0 Karma

a212830
Champion

Thanks. Some good info, but it doesn't cover how to move a windows index to a unix index. Is that possible?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...