Migrating from a Splunk 5.0.5 Heavy Forwarder to 6.x Universal Forwarder, we want to take over current checkpoints to prevent a reindexing of all events. We tried the msiexec installation parameter `migratesplunk=1` and we tried to copy the fishbucket and persistentstorage before and after the setup, but all without success.
What can we do to save the checkpoints due to the migration?
↧