I've added a new indexer to the cluster and I would like to force replication of some older archived indexes. I'm curious if there's a way to trigger Splunk to replicate the indexes, since they are not being written to anymore, or is it better for me to just copy the index files over?
Also, any best practices on configuration for an archived index to ensure it's not wasting resources.
Thanks in advance,
David
↧