I configured my original Splunk installation to forward data to newer, faster hardware but noticed only data after this change has been forwarded. How do I move over all the other data that has been indexed on the original server up to that point?
Also, how do I configure the original Splunk installation to be a regular forwarder? I want the Splunk receiver to handle indexing and searching only.
Hi wbordeau
maybe this helps:
http://www.splunk.com/wiki/Deploy:Migrating_a_Splunk_Install
http://www.splunk.com/base/Documentation/latest/Admin/Moveanindex
regards
addition: your old indexer will only forward new data, the old already indexed data will stay.