Splunk Search

Migrate data from standalone to indexer cluster

rjfv8205
Path Finder

Hello splunkers!

We have lost indexed data of some days in clustered indexer. However, data exists in standalone splunk.

How migrate it?

Tags (1)
0 Karma

ddrillic
Ultra Champion

Based on Transfer indexed data from standalone Splunk instance to clustered index.

I like the following idea -

-- However, if you just want the old data to be searchable in the new setup, you can add the old instance as a non clustered search peer on the search head.

0 Karma

rjfv8205
Path Finder

It's not all the data. I know about buckets but i don't know work them. Copy hot, warm o all the buckets?

0 Karma

ddrillic
Ultra Champion

Not sure what you mean by saying - It's not all the data. But for all the data within the standalone Splunk instance, this solution will make it available.

0 Karma

rjfv8205
Path Finder

I mean that we want data from specific days only.

Sorry my english is a little bad

0 Karma

somesoni2
Revered Legend

If on the old standalone instance, no data ingestion is happening, you can just restart Splunk on it, so that all hot buckets will move to warm. Then you can just copy warm and cold buckets to your cluster. Again, if you didn't customize your indexes.conf to roll your hot buckets to warm with span of 24 hr, then a bucket can have data for multiple days. Choosing specific days won't be possible in that case.

0 Karma

teunlaan
Contributor

If you're not rolling your buckets every single day, it is hard to get the correct buckets of the system.

What I can think off you could do:
1) export the data (in _raw) and reindex it in your cluster OR
2) user the "|collect " command to move ONLY the data you need to a new index on your standalone server. And compy the complete directory of the new index to one of your cluster systems (data won't be replicated, i I remeber it well)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...