Hi All,
We have two different Splunk environment one is Unix and another is in Windows. Is their way to read (search) the indexes cross platform. Please let us know how to configure this.
Thanks
Sathish Rangan
Hi Sathish,
You can move the index files between Unix and Windows systems. The main thing you need to be concerned about is that you can't move buckets created by a 64-bit version of Splunk to a system running 32-bit.
Instructions for doing so can be found at http://docs.splunk.com/Documentation/Splunk/6.2.4/Indexer/Moveanindex . Also read the following Splunk > answers post, http://answers.splunk.com/answers/32176/is-it-possible-to-migrate-indexed-buckets-to-a-different-ind...
Cheers,
Simon
Thank you sduff,
But we dont want to move the index just want to read(search) the data from another platform(search head)
Thanks
Sathish Rangan
Ah, OK, if I understand you, Splunk does that easily.
You want to use Distributed Search, which configures your search head to query the data stored on the indexers. http://docs.splunk.com/Documentation/Splunk/6.2.4/DistSearch/Configuredistributedsearch#Use_Splunk_W...
There are no issues with different OSs or environments communicating with one another.
thank you sduff .. will try that.