Splunk Search

Index migration event count becomes 3x more

coreyCLI
Path Finder

I recently migrated a clustered index.  We wanted to rename the index.  I created the new index as your normally would via the CM.  Put the cluster in maintenance mode.  Stop any ingest into the "old" index and merely copied all the contents of the "old" index into the "new" index on all 6 of our indexers.  Took the cluster out of maintenance mode and did a rolling restart.  Everything worked fine except when I count the events in both indexes for ALL TIME, the old index is ~40 million events and the new index is ~111 million events.  We have a SF & RF of 3.  My thoughts are that its something with the RF of 3 however the math does not really workout to be 3x.  

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...