Installation

How to migrate data from the "main" index on Splunk server B to an index named "networking" on Splunk server A?

scott778
Explorer

We've recently combined with another company that had a Splunk installation (B), just one server collecting network device info into the main index. We have a Splunk installation (A) which has multiple indexes, including one for networking. I'd like to take all the data from the main index on B and move it into the networking index on A.

Both machines are Windows 2012 R2. Those network devices that were reporting to instance B have been redirected to instance A so server B is receiving no new data.

I attempted moving the db_* folders from ./main/db on server B to the index named networking on server A and restarted the splunkd service, but still cannot search this data.

I've searched Splunk Answers and found many topics about moving to another index of the same name, but not to an index with a different name. Any help you can provide would be much appreciated.

Labels (1)
Tags (2)
0 Karma

scott778
Explorer

Yes, we are licensed for 10gb a day and only hitting about 7. I'm not sure what you mean by re-indexing the data. How can I accomplish that?

0 Karma

koshyk
Super Champion

do you have enough license? if yes, just reindex the data over a weekend again would be simpler

0 Karma

gokadroid
Motivator

Have a look here please and see if that's what you are looking for:

https://answers.splunk.com/answers/3795/can-i-merge-data-buckets-from-multiple-indexes-or-indexers.h...

0 Karma

scott778
Explorer

Do I need to check for conflicts outside of the index I'm trying to place the db folders in? If not, then yes I checked for conflicts.

0 Karma

scott778
Explorer

I've copied the db_ folders into the index networking but still cannot search the data.

0 Karma

gokadroid
Motivator

Did u check if there were any bucket id conflicts which the link talks about which needed to be renamed on movement.?

0 Karma

scott778
Explorer

I've copied the db_* folders from db into the index networking on server A but still cannot search the data.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...