Getting Data In

How to condense data from 4 non-clustered indexers that are set up as VMs into a single dedicated hardware server?

john_miller1
Explorer

I currently have 4 indexers setup as VMs. Each indexer has dedicated LUNs for their data. I'm trying to find a way to preserve data while condensing the 4 virtual indexers into a single dedicated hardware host. Any fairly straight forward method to do so or is it a situation where I am better off keeping them for historical purposes for a year (PCI data) and have all of my forwarders just start writing to the new indexer?

Tags (2)
0 Karma
1 Solution

effem
Communicator

A way to do so, would be, to roll everything over to archive (frozen) and reindex it on the new host.

See http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Automatearchiving
and: http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Restorearchiveddata

This is not tied to the origin indexer. So there will be no problem with bucket-id's and stuff.
The only problem is the time you need, to roll it over and back again.

View solution in original post

effem
Communicator

A way to do so, would be, to roll everything over to archive (frozen) and reindex it on the new host.

See http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Automatearchiving
and: http://docs.splunk.com/Documentation/Splunk/6.2.1/Indexer/Restorearchiveddata

This is not tied to the origin indexer. So there will be no problem with bucket-id's and stuff.
The only problem is the time you need, to roll it over and back again.

john_miller1
Explorer

Outstanding, thanks for info! I'll give this a shot!

0 Karma

effem
Communicator

Don't forget to add a partition to your "frozen"-directory e.g. giving it a folder in your indexes.conf.

If you miss that, your data will be deleted!

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...