<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Migrating Splunk Enterprise from RHEL to Windows in Security</title>
    <link>https://community.splunk.com/t5/Security/Migrating-Splunk-Enterprise-from-RHEL-to-Windows/m-p/709588#M18290</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Yes, you read it right. One of my small lab is planning to migrate their Splunk deployment from RHEL to Windows. Their main reason is, they do not have a Linux admin.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am going to help them migrate but I am Linux admin and never done any migration from one platform to another. Has anyone done that? Any tips on how to go about doing it?&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jan 2025 13:51:55 GMT</pubDate>
    <dc:creator>jkamdar</dc:creator>
    <dc:date>2025-01-23T13:51:55Z</dc:date>
    <item>
      <title>Migrating Splunk Enterprise from RHEL to Windows</title>
      <link>https://community.splunk.com/t5/Security/Migrating-Splunk-Enterprise-from-RHEL-to-Windows/m-p/709588#M18290</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Yes, you read it right. One of my small lab is planning to migrate their Splunk deployment from RHEL to Windows. Their main reason is, they do not have a Linux admin.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am going to help them migrate but I am Linux admin and never done any migration from one platform to another. Has anyone done that? Any tips on how to go about doing it?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 13:51:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Migrating-Splunk-Enterprise-from-RHEL-to-Windows/m-p/709588#M18290</guid>
      <dc:creator>jkamdar</dc:creator>
      <dc:date>2025-01-23T13:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating Splunk Enterprise from RHEL to Windows</title>
      <link>https://community.splunk.com/t5/Security/Migrating-Splunk-Enterprise-from-RHEL-to-Windows/m-p/709596#M18291</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/135271"&gt;@jkamdar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Windows could be ok for a lab, not for a production system!&lt;/P&gt;&lt;P&gt;First question: is a stand-alone server or a distributed environment?&lt;/P&gt;&lt;P&gt;If a stand-alone server it's simple and&amp;nbsp;I can give you some tips:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;start from the same Splunk Version,&lt;/LI&gt;&lt;LI&gt;copy the apps from the old to the new one,&lt;/LI&gt;&lt;LI&gt;modify eventual monitor inputs using the new path&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;If instead it's a distributed environment, you can copy the indexes.conf files in one app containing all the indexes definitions, and all the apps in the search Heads.&lt;/P&gt;&lt;P&gt;For the cluster or distributed search configurations,it's easier start as a new infrastructure, configuring all the connections.&lt;/P&gt;&lt;P&gt;These are few pillows but the easiest way is to start from the beginning copying one by one the indexes files.&lt;/P&gt;&lt;P&gt;The main issue is to migrate data.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 14:30:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Migrating-Splunk-Enterprise-from-RHEL-to-Windows/m-p/709596#M18291</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-23T14:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating Splunk Enterprise from RHEL to Windows</title>
      <link>https://community.splunk.com/t5/Security/Migrating-Splunk-Enterprise-from-RHEL-to-Windows/m-p/709829#M18293</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, it's a stand alone server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My comments/questions in-line below&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;start from the same Splunk Version - &lt;STRONG&gt;Yes, good point, will do that&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;copy the apps from the old to the new one - A&lt;STRONG&gt;re you referring to apps like add-ons, Splunk_TA_nix and Splunk_TA_windows?&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;modify eventual monitor inputs using the new path - &lt;STRONG&gt;Do you mean update inputs.conf?&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 13:27:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Migrating-Splunk-Enterprise-from-RHEL-to-Windows/m-p/709829#M18293</guid>
      <dc:creator>jkamdar</dc:creator>
      <dc:date>2025-01-27T13:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating Splunk Enterprise from RHEL to Windows</title>
      <link>https://community.splunk.com/t5/Security/Migrating-Splunk-Enterprise-from-RHEL-to-Windows/m-p/709835#M18294</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/135271"&gt;@jkamdar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;About the apps to migrate, I mean all the apps not contained in the Splunk installation, if you install the same version of Splunk, you could copy the full $SPLUNK_HOME/etc/apps folder.&lt;/P&gt;&lt;P&gt;beware to the last point: if in your apps there is some path, you have to manually modify paths to adapt them from linux to Windows, e.g. splunk internal logs must be moved from /opt/splunk/var/log/splunk to C:\Program Files\splunk\var\log\splunk.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 13:39:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Migrating-Splunk-Enterprise-from-RHEL-to-Windows/m-p/709835#M18294</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-27T13:39:17Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating Splunk Enterprise from RHEL to Windows</title>
      <link>https://community.splunk.com/t5/Security/Migrating-Splunk-Enterprise-from-RHEL-to-Windows/m-p/709837#M18295</link>
      <description>&lt;P&gt;Thanks, appreciate the help.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 13:58:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Migrating-Splunk-Enterprise-from-RHEL-to-Windows/m-p/709837#M18295</guid>
      <dc:creator>jkamdar</dc:creator>
      <dc:date>2025-01-27T13:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating Splunk Enterprise from RHEL to Windows</title>
      <link>https://community.splunk.com/t5/Security/Migrating-Splunk-Enterprise-from-RHEL-to-Windows/m-p/709838#M18296</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/135271"&gt;@jkamdar&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;let me know if I can help you more, or, please, accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 14:14:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Migrating-Splunk-Enterprise-from-RHEL-to-Windows/m-p/709838#M18296</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-27T14:14:25Z</dc:date>
    </item>
  </channel>
</rss>

