We currently have a single Splunk server with a large storage array. We're in the process of building out a new Splunk 5 cluster. What's the best process for getting my old data into the new cluster? Do I make the cluster a license slave of the old server and then just enable forwarding on the old server to the new cluster? Will that cause all of my old indexed data to migrate to the new cluster without blowing through the license?
Thx.
C