Splunk Search

Index migration event count becomes 3x more

coreyCLI
Path Finder

I recently migrated a clustered index.  We wanted to rename the index.  I created the new index as your normally would via the CM.  Put the cluster in maintenance mode.  Stop any ingest into the "old" index and merely copied all the contents of the "old" index into the "new" index on all 6 of our indexers.  Took the cluster out of maintenance mode and did a rolling restart.  Everything worked fine except when I count the events in both indexes for ALL TIME, the old index is ~40 million events and the new index is ~111 million events.  We have a SF & RF of 3.  My thoughts are that its something with the RF of 3 however the math does not really workout to be 3x.  

Labels (2)
0 Karma
Get Updates on the Splunk Community!

New Splunk Observability innovations: Deeper visibility and smarter alerting to ...

You asked, we delivered. Splunk Observability Cloud has several new innovations giving you deeper visibility ...

Synthetic Monitoring: Not your Grandma’s Polyester! Tech Talk: DevOps Edition

Register today and join TekStream on Tuesday, February 28 at 11am PT/2pm ET for a demonstration of Splunk ...

Instrumenting Java Websocket Messaging

Instrumenting Java Websocket MessagingThis article is a code-based discussion of passing OpenTelemetry trace ...