Splunk Enterprise

How do I move VER.9.0.2 data to Ver.7.3.3? I cover it up?

minpd0309
Explorer

Can I overwrite the data I accumulated in Ver.9.0.2 Enterprise to Ver.7.3.3 Enterprise?

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Adding to @scelikok 's answer - you can't (or at least not without some heavy splunk internal developer level magic) convert index file from a higher tsidx level to a lower one.

7.3.x does support tsidx levels of 1, 2 and 3 whereas 9.0.x supports 1, 2, 3 and 4. If your 9.0.2 indexes are configured with the default level of 3, you _might_ be able to move your data.

Having said that - why would you want to use so obsolete version which has no support and lacks many features?

scelikok
SplunkTrust
SplunkTrust

Hi @minpd0309,

It depends on indexes.conf configurations. The most critical parameters are below;

indexes.conf

tsidxWritingLevel = [1|2|3]
7.3.3 default is 1
9.0.2 default is 3

journalCompression = gzip|lz4|zstd
7.3.3 default is gzip
9.0.2 default is zstd

 If you are using 9.0.2 defaults on your 7.3.3 you can try. But if not unfortunately you cannot copy.

If parameters are the same,  it is better to try on a seperate test server first.

If this reply helps you an upvote and "Accept as Solution" is appreciated.

minpd0309
Explorer

please answer me  T . T TTTTTTTTTTTTTTTTTTT

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...