Splunk Search

Hard Disk Change on the Indexers

athorat
Communicator

We have a clustered environment.
3 Indexers , 1 search head, 1 cluster master , 4 heavy forwarders and 100+ universal forwarders
The Infrastructure team wants to change the Hard Drives on the existing Splunk Infrastructure.

How can we move the indexer data/information from one hard drive to another without any data loss.

Thanks.

Tags (1)
0 Karma

MuS
Legend

Hi athorat,

take a look at the docs http://docs.splunk.com/Documentation/Splunk/6.3.0/Indexer/Moveanindex about moving an index to a different file system / disk. As well take a look at this answer http://answers.splunk.com/answers/149248/how-to-move-index-from-one-hard-drive-to-another-in-splunk-... which covers the cluster index move.

Hope this helps ...

cheers, MuS

0 Karma

athorat
Communicator

Hi @MuS

We will not be changing the actual physical servers.
In this case when we get a new HDD can we not just replicate the content on the drive and use the new Drive?
Not sure if it makes sense...

Thanks.

0 Karma

MuS
Legend

Hi athorat,

sure, this can be done as well. Just make sure the $SPLUNK_DB path matches the new disks and all is good.

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...