Splunk Enterprise

What is Best Practice to move data from one indexer to another

SplunkySplunk
Explorer

Hello
I have an on prem indexer which i want to shot down and move all his context to another indexer is Azure
What is the best practice for that ?

Thanks

Labels (2)
Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @SplunkySplunk,

as you can find in https://docs.splunk.com/Documentation/Splunk/9.0.0/Indexer/Moveanindex#:~:text=You%20can%20move%20th....

the steps are the following:

  • install on Azure the same version of your on-premise Splunk,
  • copy all the apps in the new enviuronment, with special attention to the ones containing indexes.conf files,
  • with a down Splunk (in both systems) copy the content of your SPLUNK_DB folder (containing indexes) in the relative folder in Azure,
  • restart Splunk on Azure.

If you have Linux both on on-premise and Azure, you could also copy the entire Splunk folder, so in this way you copy all the configurations.

If you have Windows, you have to install the new machine anche copy two folders:

  • $SPLUNK_HOME\etc
  • the $SPLUNK_DB folder

One final hint, if possible, avoid Windows OS for production systems.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...