Splunk Search

How to migrate a bucket from a non-clustered legacy index as a standalone bucket to an indexer cluster for searching?

jlroberts
Engager

Greetings,

We recently created an indexer cluster splunk setup with a search head, master, and 4 indexers. We would like to make our legacy indexes from our old non-clustered splunk setup searchable via the cluster search head.

What is the process for moving a standalone bucket to the cluster, as a standalone bucket, so that it is searchable by the cluster search head?

Thank you,

Jeffrey L. Roberts

0 Karma
1 Solution

dwaddle
SplunkTrust
SplunkTrust

One simple option is to add your non-clustered indexers as search peers of your cluster search head. This of course means you have to keep the old environment around for a long as you want to keep searching it.

Otherwise, I think "moving buckets" is (relatively) straightforward as long as you don't duplicate bucket IDs. I would test the heck out of it first though.

Given the choice, however, I'd use "option one" above because of how much clearer / simpler it is.

View solution in original post

dwaddle
SplunkTrust
SplunkTrust

One simple option is to add your non-clustered indexers as search peers of your cluster search head. This of course means you have to keep the old environment around for a long as you want to keep searching it.

Otherwise, I think "moving buckets" is (relatively) straightforward as long as you don't duplicate bucket IDs. I would test the heck out of it first though.

Given the choice, however, I'd use "option one" above because of how much clearer / simpler it is.

ppablo
Retired

As a supplement, here's the topic from Splunk documentation that covers the first option provided by @dwaddle
http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Migratenon-clusteredindexerstoaclustereden...

0 Karma

jlroberts
Engager

I moved one bucket, by adding it to one of the indexers indexes.conf then rsyncing the directory of db_ files, however, its not searchable by the search head, how would I get the search head to be able to search that index?

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...