Splunk Search

How to migrate a bucket from a non-clustered legacy index as a standalone bucket to an indexer cluster for searching?

jlroberts
Engager

Greetings,

We recently created an indexer cluster splunk setup with a search head, master, and 4 indexers. We would like to make our legacy indexes from our old non-clustered splunk setup searchable via the cluster search head.

What is the process for moving a standalone bucket to the cluster, as a standalone bucket, so that it is searchable by the cluster search head?

Thank you,

Jeffrey L. Roberts

0 Karma
1 Solution

dwaddle
SplunkTrust
SplunkTrust

One simple option is to add your non-clustered indexers as search peers of your cluster search head. This of course means you have to keep the old environment around for a long as you want to keep searching it.

Otherwise, I think "moving buckets" is (relatively) straightforward as long as you don't duplicate bucket IDs. I would test the heck out of it first though.

Given the choice, however, I'd use "option one" above because of how much clearer / simpler it is.

View solution in original post

dwaddle
SplunkTrust
SplunkTrust

One simple option is to add your non-clustered indexers as search peers of your cluster search head. This of course means you have to keep the old environment around for a long as you want to keep searching it.

Otherwise, I think "moving buckets" is (relatively) straightforward as long as you don't duplicate bucket IDs. I would test the heck out of it first though.

Given the choice, however, I'd use "option one" above because of how much clearer / simpler it is.

ppablo
Community Manager
Community Manager

As a supplement, here's the topic from Splunk documentation that covers the first option provided by @dwaddle
http://docs.splunk.com/Documentation/Splunk/6.2.2/Indexer/Migratenon-clusteredindexerstoaclustereden...

0 Karma

jlroberts
Engager

I moved one bucket, by adding it to one of the indexers indexes.conf then rsyncing the directory of db_ files, however, its not searchable by the search head, how would I get the search head to be able to search that index?

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...