Hi,
I have all my inputs pointing at index "main" on my existing splunk server. I have added a new indexer to my splunk instance and want to move all the indexes to the main index of the new indexer. Also, want to point all the data inputs to the main index on the new indexer.
Please can you advise what would be the best way to do this?
Stop old splunk, copy over index, redirect forwarders, start new splunk?
We do not have forwarders.