Deployment Architecture

Migration of buckets from an non clustered instance to a clustered instance

ameslet
Explorer

Hi guys,

I have the following issue, I have copied the whole $SPLUNK_HOME directory from my old Splunk instance to both of my indexers which are part of the cluster I want to set up. After changing the guid in the $SPLUNK_HOME/etc/instance.cgf file, one of the indexer is not fully searchable and therefore can't be added to the cluster as all the buckets I have imported are standalone buckets.
Is it mandatory to precise the guid on the imported buckets as both of the indexers already have it ?

Do you guys know of a solution to fix the problem and avoid renaming the buckets ? I have a lot of indexes and buckets, so this solution is not foreseeable.

0 Karma

dxu_splunk
Splunk Employee
Splunk Employee

you should only have a single copy of the buckets from non-clustered splunk installs. we don't replicate your old pre-clustering buckets, so we don't expect there to be more than one copy (which is likely why the second peer wasn't allowed to add itself to the cluster).

if you want to make your old pre-clustering buckets clustered (and replicated), see

http://docs.splunk.com/Documentation/Splunk/6.4.2/Indexer/Migratenon-clusteredindexerstoaclustereden...
https://answers.splunk.com/answers/106482/any-details-on-how-to-attempt-to-cluster-legacy-data-even-...

jmheaton
Path Finder

Best thing to do is to move them onto the thawed path and manually delete them when the time comes, keeping them in the default path can be tricky to get working, where as thawed it will usually be fine.
We are having the same issue moving from standalone indexers to clustered indexers, we did the above and let it ride until our retention period was complete.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...