Splunk Search

How to migrate a bucket from a non-clustered legacy index as a standalone bucket to an indexer cluster for searching?

jlroberts
Engager

Greetings,

We recently created an indexer cluster splunk setup with a search head, master, and 4 indexers. We would like to make our legacy indexes from our old non-clustered splunk setup searchable via the cluster search head.

What is the process for moving a standalone bucket to the cluster, as a standalone bucket, so that it is searchable by the cluster search head?

Thank you,

Jeffrey L. Roberts

0 Karma
1 Solution

dwaddle
SplunkTrust
SplunkTrust

One simple option is to add your non-clustered indexers as search peers of your cluster search head. This of course means you have to keep the old environment around for a long as you want to keep searching it.

Otherwise, I think "moving buckets" is (relatively) straightforward as long as you don't duplicate bucket IDs. I would test the heck out of it first though.

Given the choice, however, I'd use "option one" above because of how much clearer / simpler it is.

View solution in original post

dwaddle
SplunkTrust
SplunkTrust

One simple option is to add your non-clustered indexers as search peers of your cluster search head. This of course means you have to keep the old environment around for a long as you want to keep searching it.

Otherwise, I think "moving buckets" is (relatively) straightforward as long as you don't duplicate bucket IDs. I would test the heck out of it first though.

Given the choice, however, I'd use "option one" above because of how much clearer / simpler it is.

ppablo
Retired

As a supplement, here's the topic from Splunk documentation that covers the first option provided by @dwaddle
http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Migratenon-clusteredindexerstoaclustereden...

0 Karma

jlroberts
Engager

I moved one bucket, by adding it to one of the indexers indexes.conf then rsyncing the directory of db_ files, however, its not searchable by the search head, how would I get the search head to be able to search that index?

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...