Splunk Search

How to migrate a bucket from a non-clustered legacy index as a standalone bucket to an indexer cluster for searching?

jlroberts
Engager

Greetings,

We recently created an indexer cluster splunk setup with a search head, master, and 4 indexers. We would like to make our legacy indexes from our old non-clustered splunk setup searchable via the cluster search head.

What is the process for moving a standalone bucket to the cluster, as a standalone bucket, so that it is searchable by the cluster search head?

Thank you,

Jeffrey L. Roberts

0 Karma
1 Solution

dwaddle
SplunkTrust
SplunkTrust

One simple option is to add your non-clustered indexers as search peers of your cluster search head. This of course means you have to keep the old environment around for a long as you want to keep searching it.

Otherwise, I think "moving buckets" is (relatively) straightforward as long as you don't duplicate bucket IDs. I would test the heck out of it first though.

Given the choice, however, I'd use "option one" above because of how much clearer / simpler it is.

View solution in original post

dwaddle
SplunkTrust
SplunkTrust

One simple option is to add your non-clustered indexers as search peers of your cluster search head. This of course means you have to keep the old environment around for a long as you want to keep searching it.

Otherwise, I think "moving buckets" is (relatively) straightforward as long as you don't duplicate bucket IDs. I would test the heck out of it first though.

Given the choice, however, I'd use "option one" above because of how much clearer / simpler it is.

ppablo
Retired

As a supplement, here's the topic from Splunk documentation that covers the first option provided by @dwaddle
http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Migratenon-clusteredindexerstoaclustereden...

0 Karma

jlroberts
Engager

I moved one bucket, by adding it to one of the indexers indexes.conf then rsyncing the directory of db_ files, however, its not searchable by the search head, how would I get the search head to be able to search that index?

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...