Knowledge Management

moving a summary index

a212830
Champion

Hi,

One of my customers has a summary index running on a POC that they want to move into my production system. The summary index is on a 4.3 system (windows), and the production system is running on 5.01 (linux). Is it possible to move it? Can I also rename it?

Tags (2)
0 Karma

bmacias84
Champion

Yes, Answer is yes to both questions. Move an index is similar to the process of backup and restoring indexes. Regarding renaming an index I have never don't it but hopefully the links will help you. Dont forget to make sure file system permission are set correctly when migrating.

Here are some docs that will help:

Hope this helps or gets you started. Dont forget to accept answers and vote on answers that help.

Cheers,

bmacias84
Champion

I would gzip and rsyn the directors over to the linux server in the appropriate directory. Make sure ur migrated index is set in the indexes.conf.. Set your permissions use cown and chmod. Both servers must gave splunkd stop while doing this. Permissions need to be correct as ntfs perms will not match or carry over.

0 Karma

a212830
Champion

Thanks. Some good info, but it doesn't cover how to move a windows index to a unix index. Is that possible?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...