Splunk® Enterprise

Managing Indexers and Clusters of Indexers

Download manual as PDF

Splunk Enterprise version 5.0 reached its End of Life on December 1, 2017. Please see the migration information.
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

Migrate non-clustered indexers to a clustered environment

Read the topic "Key differences between clustered and non-clustered Splunk deployments" carefully if you plan to migrate your current set of indexers to a cluster. That topic describes issues that you must understand before initiating the migration process.

You can add a non-clustered indexer to a cluster (as a peer node) at any time. To do so, just enable the indexer as a peer, as described in "Enable the peer nodes".

Once the indexer has been made a peer, it participates in the cluster the same as any other peer. Any new data coming into the peer gets replicated according to the cluster's replication factor, and the peer is also a candidate for receiving replicated data from other peers. Data already on the indexer does not get automatically replicated, but it does participate in searches, as described below.

How the cluster handles legacy indexed data

When you add an existing indexer to the cluster, the cluster does not replicate any buckets that are already on the indexer.

Buckets already on the indexer prior to its being added to the cluster are called "standalone" buckets. Searches will still occur across those buckets and will be combined with search results from the cluster's replicated buckets.

Is there any way to migrate my legacy data?

Because of the high processing cost of converting standalone buckets to replicated buckets (due to the need to make multiple searchable and non-searchable copies of those buckets to fulfill the cluster's replication and search factors), it is generally a bad idea to attempt to do so, particularly in the case of indexers with large numbers of standalone buckets. There is no supported procedure for this conversion. If you are interested in having this performed, please contact Splunk Professional Services to discuss the trade-offs and requirements for this operation.

Use clusters to scale indexing
Configure the master

This documentation applies to the following versions of Splunk® Enterprise: 5.0, 5.0.1


I expected to learn how to migrate existing indexes to clustered ones. Not one word about this important issue!<br />If you just add a non-clustered indexer to a cluster environment, it will fetch the configuration bundle from the master node. All existing indexes stay local to an indexer except there are appropriate entries in the configuration bundle. Therefore I expect you have to collect the index stanzas from the various places on the indexer ($SPLUNK_HOME/etc/system/local/indexes.conf, $SPLUNK_HOME/etc/apps/*/local/indexes.conf) and add them to the central configuration to get them replicated.<br />I'm also not so sure about the handling of existing buckets, if you apply such a cooked indexes.conf. You state that they are left alone and not included in the replication and I pray that is true.

January 4, 2013

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters