Splunk Enterprise

How do I move VER.9.0.2 data to Ver.7.3.3? I cover it up?

minpd0309
Explorer

Can I overwrite the data I accumulated in Ver.9.0.2 Enterprise to Ver.7.3.3 Enterprise?

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Adding to @scelikok 's answer - you can't (or at least not without some heavy splunk internal developer level magic) convert index file from a higher tsidx level to a lower one.

7.3.x does support tsidx levels of 1, 2 and 3 whereas 9.0.x supports 1, 2, 3 and 4. If your 9.0.2 indexes are configured with the default level of 3, you _might_ be able to move your data.

Having said that - why would you want to use so obsolete version which has no support and lacks many features?

scelikok
SplunkTrust
SplunkTrust

Hi @minpd0309,

It depends on indexes.conf configurations. The most critical parameters are below;

indexes.conf

tsidxWritingLevel = [1|2|3]
7.3.3 default is 1
9.0.2 default is 3

journalCompression = gzip|lz4|zstd
7.3.3 default is gzip
9.0.2 default is zstd

 If you are using 9.0.2 defaults on your 7.3.3 you can try. But if not unfortunately you cannot copy.

If parameters are the same,  it is better to try on a seperate test server first.

If this reply helps you an upvote and "Accept as Solution" is appreciated.

minpd0309
Explorer

please answer me  T . T TTTTTTTTTTTTTTTTTTT

0 Karma
Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...