Splunk Dev

Migrate Index without shutdown

mdmurtazaali
New Member

Hi There, We have two indexer (not clustered) but on DNS roundrobin. We need to migrate the indexers to the new hardware and we are planning to do that one by one. For indexer 1 Is there any way to:
1. Copy the files to the new server without shutting down splunk?
2. Can the indexer 1 be readonly from search head?

Thanks,

Mo

Tags (1)
0 Karma
1 Solution

jcrabb_splunk
Splunk Employee
Splunk Employee

Here is our documentation that discusses migrating:

http://docs.splunk.com/Documentation/Splunk/6.5.2/Installation/MigrateaSplunkinstance

As you will see in this section, you will need to stop Splunk:

1. Stop Splunk Enterprise on the host from which you want to migrate.
2. Copy the entire contents of the $SPLUNK_HOME directory from the old host to the new host.
3. Install the appropriate version of Splunk Enterprise for the target platform.
4. Confirm that index configuration files (indexes.conf) contain the correct location and path specification for any non-default indexes.
5. Start Splunk Enterprise on the new instance.
6. Log into Splunk Enterprise with your existing credentials.
7. After you log in, confirm that your data is intact by searching it.

While you can make an index read-only, in order to migrate properly, you will need to stop Splunk.

Jacob
Sr. Technical Support Engineer

View solution in original post

puneethgowda
Communicator

Answer for your question is downtime is must

0 Karma

jcrabb_splunk
Splunk Employee
Splunk Employee

Here is our documentation that discusses migrating:

http://docs.splunk.com/Documentation/Splunk/6.5.2/Installation/MigrateaSplunkinstance

As you will see in this section, you will need to stop Splunk:

1. Stop Splunk Enterprise on the host from which you want to migrate.
2. Copy the entire contents of the $SPLUNK_HOME directory from the old host to the new host.
3. Install the appropriate version of Splunk Enterprise for the target platform.
4. Confirm that index configuration files (indexes.conf) contain the correct location and path specification for any non-default indexes.
5. Start Splunk Enterprise on the new instance.
6. Log into Splunk Enterprise with your existing credentials.
7. After you log in, confirm that your data is intact by searching it.

While you can make an index read-only, in order to migrate properly, you will need to stop Splunk.

Jacob
Sr. Technical Support Engineer

mdmurtazaali
New Member

Thanks @Jcrabb!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...