Splunk Search

How to migrate a bucket from a non-clustered legacy index as a standalone bucket to an indexer cluster for searching?

jlroberts
Engager

Greetings,

We recently created an indexer cluster splunk setup with a search head, master, and 4 indexers. We would like to make our legacy indexes from our old non-clustered splunk setup searchable via the cluster search head.

What is the process for moving a standalone bucket to the cluster, as a standalone bucket, so that it is searchable by the cluster search head?

Thank you,

Jeffrey L. Roberts

0 Karma
1 Solution

dwaddle
SplunkTrust
SplunkTrust

One simple option is to add your non-clustered indexers as search peers of your cluster search head. This of course means you have to keep the old environment around for a long as you want to keep searching it.

Otherwise, I think "moving buckets" is (relatively) straightforward as long as you don't duplicate bucket IDs. I would test the heck out of it first though.

Given the choice, however, I'd use "option one" above because of how much clearer / simpler it is.

View solution in original post

dwaddle
SplunkTrust
SplunkTrust

One simple option is to add your non-clustered indexers as search peers of your cluster search head. This of course means you have to keep the old environment around for a long as you want to keep searching it.

Otherwise, I think "moving buckets" is (relatively) straightforward as long as you don't duplicate bucket IDs. I would test the heck out of it first though.

Given the choice, however, I'd use "option one" above because of how much clearer / simpler it is.

ppablo
Retired

As a supplement, here's the topic from Splunk documentation that covers the first option provided by @dwaddle
http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Migratenon-clusteredindexerstoaclustereden...

0 Karma

jlroberts
Engager

I moved one bucket, by adding it to one of the indexers indexes.conf then rsyncing the directory of db_ files, however, its not searchable by the search head, how would I get the search head to be able to search that index?

0 Karma
Get Updates on the Splunk Community!

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...

Stay Connected: Your Guide to October Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...