Splunk Enterprise Security

How to migrate data in an indexer cluster to a new indexer cluster environment?

syazwani
Path Finder

Hi peeps,

I need some information about migrating data from an instance in a cluster environment to a new cluster environment. I was unable to find documentation about this process, so I would like to get some advice or pros/cons details from the experts. Please help.

Thank you. 

Labels (2)

MaverickT
Communicator

The easiest option is to add new indexers/nodes to existing cluster, sync existing data to this nodes and after that slowly retire old indexers using "splunk offline --enforce-counts" command.

isoutamo
SplunkTrust
SplunkTrust
https://community.splunk.com/t5/Splunk-Enterprise/Migration-of-Splunk-to-different-server-same-platf... this links contains those exact steps which are needed including remove old peers from CM! As "splunk offline --enforce-counts" is not enough.
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

can you describe more about your current and target environment?

Are you replacing current one with then new cluster (see: https://community.splunk.com/t5/Splunk-Enterprise/Migration-of-Splunk-to-different-server-same-platf...)? 

Are both clusters using same OS (type like linux) and splunk version?

Online or offline migration is preferred and how much time you have for it?

r. Ismo

0 Karma

syazwani
Path Finder

Hi @isoutamo,

Thanks for replying. Our current environment is multisite indexer cluster environment and we will plan to decommission the system with hardware. Our target environment is also multisite indexer cluster with new hardware. 

We are not replacing the new environment, we are migration to new environment. We are planning to cutover to the new cluster approcahes.

We are using the same OS and the splunk version will be from 8.2 to 8.3

We are going for online migration and we dont have a specific time period.

Thank you.

 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Here is the way how I have done this kind of operations. 

https://community.splunk.com/t5/Splunk-Enterprise/Migration-of-Splunk-to-different-server-same-platf...

I think that it's the easiest way to do it and basically no real service break to end users.

You should use just those indexer cluster parts from this workflow.

If you are doing Splunk version update, then you should do it before or after the migration not at same time!

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...