Deployment Architecture

Migration of buckets from an non clustered instance to a clustered instance

ameslet
Explorer

Hi guys,

I have the following issue, I have copied the whole $SPLUNK_HOME directory from my old Splunk instance to both of my indexers which are part of the cluster I want to set up. After changing the guid in the $SPLUNK_HOME/etc/instance.cgf file, one of the indexer is not fully searchable and therefore can't be added to the cluster as all the buckets I have imported are standalone buckets.
Is it mandatory to precise the guid on the imported buckets as both of the indexers already have it ?

Do you guys know of a solution to fix the problem and avoid renaming the buckets ? I have a lot of indexes and buckets, so this solution is not foreseeable.

0 Karma

dxu_splunk
Splunk Employee
Splunk Employee

you should only have a single copy of the buckets from non-clustered splunk installs. we don't replicate your old pre-clustering buckets, so we don't expect there to be more than one copy (which is likely why the second peer wasn't allowed to add itself to the cluster).

if you want to make your old pre-clustering buckets clustered (and replicated), see

http://docs.splunk.com/Documentation/Splunk/6.4.2/Indexer/Migratenon-clusteredindexerstoaclustereden...
https://answers.splunk.com/answers/106482/any-details-on-how-to-attempt-to-cluster-legacy-data-even-...

jmheaton
Path Finder

Best thing to do is to move them onto the thawed path and manually delete them when the time comes, keeping them in the default path can be tricky to get working, where as thawed it will usually be fine.
We are having the same issue moving from standalone indexers to clustered indexers, we did the above and let it ride until our retention period was complete.

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...