Splunk Enterprise

How do I move VER.9.0.2 data to Ver.7.3.3? I cover it up?

minpd0309
Explorer

Can I overwrite the data I accumulated in Ver.9.0.2 Enterprise to Ver.7.3.3 Enterprise?

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Adding to @scelikok 's answer - you can't (or at least not without some heavy splunk internal developer level magic) convert index file from a higher tsidx level to a lower one.

7.3.x does support tsidx levels of 1, 2 and 3 whereas 9.0.x supports 1, 2, 3 and 4. If your 9.0.2 indexes are configured with the default level of 3, you _might_ be able to move your data.

Having said that - why would you want to use so obsolete version which has no support and lacks many features?

scelikok
SplunkTrust
SplunkTrust

Hi @minpd0309,

It depends on indexes.conf configurations. The most critical parameters are below;

indexes.conf

tsidxWritingLevel = [1|2|3]
7.3.3 default is 1
9.0.2 default is 3

journalCompression = gzip|lz4|zstd
7.3.3 default is gzip
9.0.2 default is zstd

 If you are using 9.0.2 defaults on your 7.3.3 you can try. But if not unfortunately you cannot copy.

If parameters are the same,  it is better to try on a seperate test server first.

If this reply helps you an upvote and "Accept as Solution" is appreciated.

minpd0309
Explorer

please answer me  T . T TTTTTTTTTTTTTTTTTTT

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...