Hi @mshakeb ,
if you haven't an Indexer Cluster, you have to:
For more infos, you can see at https://docs.splunk.com/Documentation/Splunk/9.2.1/Indexer/Moveanindex
Ciao.
Giuseppe
Thanks for the response.
we do not want downtime, please find the below steps on
Old Splunk indexers
New Splunk Servers
1. Prepare 3 New indexers and a New CM
2. On New Indexers Storage path for Hot & warn data is
/splunk_hot and /splunk_cold
Plan for Migration from old to New (without down-time)
Example : ln -s /opt/splunk/var/lib/splunk/….. /splunk_hot (I am not sure here)
[volume_primary]
#Path = /opt/splunk/var/lib/splunk (this is old path and it is committed)
Path = /splunk_hot
[volume_cold]
#Path = /opt/splunk/var/lib/splunk (this is old path and it is committed)
Path = /splunk_cold
I am Struck here
I want to create a symbolic link on old indexers servers, how could I create and point the hot data to move in /splunk_hot and colddb to /splunk_cold
I can see in the old indexers they are lots on index available (like windows,Linux,security,waf,firewall)
Hi @mshakeb,
having an Indexer Cluster, the best solution is adding three new Indexers to the old CM using RF=3 and SF=3, in this way, after some time) in the new three Indexers you will have a complete set of data.
When data will be replicated in the new indexers, remove, one by one the three old Indexers, then change RF and SR as original.
At least replace the CM following the documentation.
Plan with much attention these activities!
Ciao.
Giuseppe