We are running a distributed clustered Splunk environment on version 6.2
We are planning to upgrade to 6.3 due to definitive requirements.
As part of the upgrade instructions, it is mentioned to take a backup of files/indexed data and configurations.
We could not find any instructions on how to back up and restore the indexed data.
We are running on a Unix environment and have a large amount of data coming in (in TB) daily.
Any instructions on how to back up and then restore after upgrade?
Also the instructions say all Indexer peers should be stopped..we are skeptical about this, since it will lead to loss of data. Any other alternative?
↧