<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Migration from RHEL to AL2023 in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749274#M22579</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Agreed, however, when i start the Splunk after accepting the license agreement, i run into the following screenshot which takes care of the seamless migration, I believe what I'm doing must be a documented procedure and nothing unusual and it also creates a migration logs with the details of what was done during the process... please lemme know your thoughts!!&lt;BR /&gt;&lt;BR /&gt;Thanks for your help &amp;amp; Happy 4th!!&lt;BR /&gt;&lt;BR /&gt;Download migration log from here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://limewire.com/d/Jd4GD#NEdMoeWwVg" target="_blank" rel="noopener"&gt;https://limewire.com/d/Jd4GD#NEdMoeWwVg&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="venksel1_0-1751671605628.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39573iC73FD581950BAC40/image-size/medium?v=v2&amp;amp;px=400" role="button" title="venksel1_0-1751671605628.png" alt="venksel1_0-1751671605628.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jul 2025 23:38:20 GMT</pubDate>
    <dc:creator>venksel1</dc:creator>
    <dc:date>2025-07-04T23:38:20Z</dc:date>
    <item>
      <title>Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748491#M22466</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;We've a standalone Splunk instance v8.2.2.1 deployed on a&amp;nbsp; RHEL server which is EOL; we wish to migrate to a newer OS Amazon Linux (AL) 2023 OS--&amp;nbsp;rather than&amp;nbsp; performing an in-place upgrade. Instead of using the most recent version of Splunk enterprise, we still wish to adopt a more conservative approach and choose 9.0.x (we've UFs that are older version 7.x and 8.x). Please let me know where can i download 9.0.x version of Splunk enterprise as it's not here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/download/previous-releases.html" target="_blank" rel="noopener"&gt;https://www.splunk.com/en_us/download/previous-releases.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 13:14:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748491#M22466</guid>
      <dc:creator>venksel</dc:creator>
      <dc:date>2025-06-23T13:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748493#M22467</link>
      <description>&lt;P&gt;Contact Splunk Support for versions not available on the web site.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 14:12:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748493#M22467</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2025-06-23T14:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748505#M22468</link>
      <description>&lt;P&gt;And why would you go for 9.0 which is out of support? I'd strongly advise against that. Unless you have a very good reason for doing so (and a very very good support contract, other than us, mere mortals) it's unwise to keep your environment at an unsupported version (which applies to the current 8.2 as well).&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 15:01:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748505#M22468</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-06-23T15:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748506#M22469</link>
      <description>&lt;P&gt;You are going to have to contact Splunk Support for any older versions not on their website.&amp;nbsp; I apologize for that inconvenience.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It is your environment and you need to do what you and your management team feel are the best things, but as a person employed in the Cyber Security arena, I feel that I should at least mention the following.&amp;nbsp; None of this applies to your wanting to run 9.0.x&amp;nbsp; It was the Splunk 7 and Splunk 8 that raised my antennae.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Running 7.x (and to a lesser extent 8.x) UFs introduces significant risks, especially since Splunk 7.x reached End of Support (EOS) between October 2020 and October 2021, and 8.2.x is also at or past end of life. Here are the key implications:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Operational Risks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Limited Functionality&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: Splunk 7.x UFs lack support for newer features like data compression, advanced SSL configurations, or Splunk-to-Splunk (S2S) Protocol V4, which 9.x indexers use by default. This can cause performance issues or data ingestion failures if configurations mismatch. For example, 7.x UFs may not handle modern event-breaking or parsing rules in 9.0.x apps.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Management Challenges&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: If you use a Deployment Server (DS), it must be 9.0.x or newer to manage 7.x/8.x UFs. Older DS versions may fail to deploy apps to newer UFs, complicating configuration management.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Stability Issues&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: 7.x UFs may encounter bugs or crashes on modern OSes (e.g., newer Linux kernels), as they were designed for older environments. Splunk Support won’t provide fixes for EOS versions, leaving you to work around issues manually.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Security Risks&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Vulnerabilities&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: 7.x UFs miss critical security patches available in 8.x and 9.x, exposing your environment to known vulnerabilities (e.g., CVE fixes). Without patches, UFs could be exploited, especially if they’re on internet-facing systems or handle sensitive data.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;SSL/TLS Weaknesses&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: 7.x UFs use outdated SSL/TLS protocols, which may conflict with 9.0.x’s stricter security defaults (e.g., TLS 1.2/1.3). This can lead to connection failures or insecure data transmission. 8.x UFs are less problematic but still lack the latest TLS enhancements in 9.x.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Compliance Issues&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: Running EOS software like 7.x may violate compliance requirements (e.g., PCI DSS, HIPAA), as auditors often flag unsupported software as non-compliant.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Recommendations for UFs&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Upgrade UFs to 9.0.x&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: Plan to upgrade your 7.x and 8.x UFs to 9.0.x (or at least 8.2.x) to align with your indexer. UFs are lightweight, and upgrades are straightforward&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Start with a few test UFs to validate compatibility with your 9.0.x indexer and DS (if used).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Use the Deployment Server to automate UF upgrades, ensuring &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;serverclass.conf&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; matches the new version.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Prioritize 7.x First&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: 7.x UFs are the most critical to upgrade due to EOS status and severe security risks. 8.x UFs are less urgent but should be updated to avoid future EOS issues.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Check Compatibility&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: Confirm UF OS compatibility with 9.0.x (e.g., AL2023 or supported Windows versions) using the Splunk System Requirements.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Interim Step&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;: If upgrading all UFs immediately isn’t feasible, ensure your 9.0.x indexer’s &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;inputs.conf&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; supports legacy S2S protocols (e.g., V3 for 7.x UFs) by setting &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;connectionTimeout&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; or &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;readTimeout&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt; to accommodate older clients. However, this is a temporary workaround.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Why Upgrade UFs?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Aligning UFs with 9.0.x ensures optimal performance, security, and supportability. Splunk 9.0.x introduces features like ingest actions and enhanced TLS validation, which 7.x UFs can’t leverage.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Upgrading avoids the risk of data loss or ingestion delays due to protocol mismatches or unpatched bugs.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;Splunk Support can assist with 9.0.x issues, but not with 7.x, reducing your troubleshooting burden.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 23 Jun 2025 15:05:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748506#M22469</guid>
      <dc:creator>LAME-Creations</dc:creator>
      <dc:date>2025-06-23T15:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748514#M22470</link>
      <description>&lt;P&gt;Actually, compression has been around for quite a long time and 7.x forwarders should support it.&lt;/P&gt;&lt;P&gt;Also, your protocol levels are way off.&lt;/P&gt;&lt;P&gt;Not to mention the bogus requirement to use 9.0+ DS to manage 7/8 version UFs.&lt;/P&gt;&lt;P&gt;Please refrain from posting AI-generated content.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jun 2025 15:35:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748514#M22470</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-06-23T15:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748748#M22475</link>
      <description>&lt;P&gt;Hi All:&lt;/P&gt;&lt;P&gt;Thank you and I appreciate your response.&lt;/P&gt;&lt;P&gt;We have a standalone instance of Splunk indexer and I double-checked and for the most part we're using 8.2.9 version of SplunkUF.&lt;/P&gt;&lt;P&gt;Additionally, since Splunk Enterprise 9.2.7 is the version in the 9.x.x family that supports Amazon Linux, we'll go for the same version.&lt;/P&gt;&lt;P&gt;Currently the indexes' physical location is spread across volumes that are mounted on the Splunk indexer host at OS level.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Please let us know if this is the right approach and if there are any stages we're missing in regards to the data cutover from the old to the new server.&lt;/P&gt;&lt;P&gt;• Install Splunk Enterprise 9.2.7 on a new AL2023 server&lt;BR /&gt;• Take a snapshot of the old server's volumes that contains indexed data, then connect them to the new one using the same mount point.&lt;BR /&gt;• Copy the entire $SPLUNK_HOME/etc directory from the old server to the new server&lt;BR /&gt;• Copy indexed data from $SPLUNK_DB (/opt/splunk/var/lib/splunk) to the new server&lt;BR /&gt;• Detach &amp;amp; attach publicIP/EIP from old to the new server&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 19:14:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748748#M22475</guid>
      <dc:creator>venksel</dc:creator>
      <dc:date>2025-06-25T19:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748757#M22476</link>
      <description>&lt;P&gt;The general idea is OK but there are details which can pop up unexpectedly here and there.&lt;/P&gt;&lt;P&gt;1. I assume (never used it myself) that Amazon Linux is also an RPM-based distro and you'll be installing Splunk the same way it was installed before.&lt;/P&gt;&lt;P&gt;2. Remember to shut down Splunk service before moving the data. And of course don't start the new instance before you copy the data.&lt;/P&gt;&lt;P&gt;3. I'm not sure why you want to snapshot the volumes. For backup in case you need to roll back?&lt;/P&gt;&lt;P&gt;4. You might have other dependencies lying around, not included in $SPLUNK_HOME - for example certificates.&lt;/P&gt;&lt;P&gt;5. If you move whole filesystems between server instances the UIDs and GIDs might not match and you might need to fix your accesses.&lt;/P&gt;&lt;P&gt;Oh, and most importantly - I didn't notice that at first - DON'T UPGRADE AND MOVE AT THE SAME TIME! Either upgrade and then do the move to the same version on a new server or move to the same 8.x you have now and then upgrade on the new server.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 20:57:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748757#M22476</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-06-25T20:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748839#M22492</link>
      <description>&lt;P&gt;&lt;BR /&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Thank you so much for your help...Please find the comments inline:&lt;/P&gt;&lt;P&gt;1. I assume (never used it myself) that Amazon Linux is also an RPM-based distro and you'll be installing Splunk the same way it was installed before.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Yes, Amazon Linux natively supports RPM package installer&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;2. Remember to shut down Splunk service before moving the data. And of course don't start the new instance before you copy the data.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Got it.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;3. I'm not sure why you want to snapshot the volumes. For backup in case you need to roll back?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Yes, correct..in case there is a need to rollback&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;4. You might have other dependencies lying around, not included in $SPLUNK_HOME - for example certificates.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;In our case, the ssl certificates are deployed under /opt/splunk/etc/certs/ as the ssl offloading is directly on the server and there is no loadbalancer or proxy in the front.&amp;nbsp; Can you think of anything else that may&amp;nbsp; deployed outside of /opt/splunk&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;5. If you move whole filesystems between server instances the UIDs and GIDs might not match and you might need to fix your accesses.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Can we recursively chown the files on the new server after migration to ensure correct ownership, hope that should take care of it&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;sudo chown -R splunk:splunk /opt/splunk&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Oh, and most importantly - I didn't notice that at first - DON'T UPGRADE AND MOVE AT THE SAME TIME! Either upgrade and then do the move to the same version on a new server or move to the same 8.x you have now and then upgrade on the new server.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Sure I prefer doing the latter, but the older version of Splunk Enterprise 8.2.2.1 does not support Amazon Linux.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 20:48:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748839#M22492</guid>
      <dc:creator>venksel</dc:creator>
      <dc:date>2025-06-26T20:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748842#M22493</link>
      <description>&lt;P&gt;4. That was the most obvious example. There might be some other dependencies - for example, if you're using dbconnect, you require JRE.&lt;/P&gt;&lt;P&gt;5. Yes, chowning should take care of it. But as I understood from your earlier comments, you have your index volume(s) outside /opt/splunk. You need to take care of its ownership as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 21:53:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748842#M22493</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-06-26T21:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748844#M22495</link>
      <description>&lt;P class="lia-align-left"&gt;I don’t believe that you have any issues with those 8.x.x UFs with splunk 9.3.x or even. 9.4.x. Those will work together, maybe some modifications are needed, but probably none.&lt;/P&gt;&lt;P class="lia-align-left"&gt;Here is one old post which points to some other post based on your environment. &amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-left"&gt;&lt;A href="https://community.splunk.com/t5/Deployment-Architecture/Splunk-Migration-from-existing-server-to-a-new-server/m-p/681655/highlight/true#M28001" target="_blank"&gt;https://community.splunk.com/t5/Deployment-Architecture/Splunk-Migration-from-existing-server-to-a-new-server/m-p/681655/highlight/true#M28001&lt;/A&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;If/when you could do a new host which you can use for some testing this shouldn’t be an issue. Just test it with test systems with instructions from those above posts. When you have check and approved those test then just do real migration.&lt;/P&gt;&lt;P class="lia-align-left"&gt;I’m not 100% sure that there is not any issues with amz2023 version. I have some feelings that there could be something which need to configure separately e.g. cgroups or something else? You probably find more details from&amp;nbsp;&lt;A href="https://splunkcommunity.slack.com/archives/C03M9ENE6AD" target="_blank"&gt;https://splunkcommunity.slack.com/archives/C03M9ENE6AD&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 22:55:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748844#M22495</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-06-26T22:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748865#M22498</link>
      <description>&lt;P&gt;Yes. The range of interoperability between UFs and receiving components (intermediate forwarders/indexers) is quite big. Even if the official documentation doesn't list something as supported, things might just work. I've had UFs as old as 6.6 sending to version 9 indexers and it ran OK. There might be a minor issue with v9 UFs sending to older indexers because new UFs generate config change events which are supposed to go to indexes not present on older Splunk instances. The temporary walkaround for this is to disable the config tracker inputs on the UFs until the indexers are upgraded to v9. But even if you don't do that, they will generally work, it's just that those events will either land in your last chance index or will generate a warning about non-existent index and get dropped completely.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jun 2025 12:31:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748865#M22498</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-06-27T12:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748896#M22500</link>
      <description>Exactly that way. And Splunk has changed requirements to have higher version in Indexers with version 9.x. (not sure which minor x was). Now you can officially have newer UF version than receiving HF/IDX version.</description>
      <pubDate>Fri, 27 Jun 2025 23:08:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/748896#M22500</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-06-27T23:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749179#M22560</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I did the following in my test environment and migration is successful. PLease let me know your thoughts on this procedure&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Installed Splunk 9.2.7 on a fresh AL2023 server, verified that the web console was accessible, and confirmed I could log in.&lt;BR /&gt;* Stopped the Splunk service&lt;BR /&gt;* Copied the /opt/splunk/etc/ and /opt/splunk/var/lib/splunk directories from the 8.2.2.1 server to the new server&lt;BR /&gt;* Mounted the necessary volumes from the old server to the new one, ensuring the index data was available&lt;BR /&gt;* Uninstalled Splunk 9.2.7&lt;BR /&gt;* Noted that, after uninstalling, the etc and db directories remained intact.&lt;BR /&gt;* Reinstalled Splunk 9.2.7&lt;BR /&gt;* During the initial start with sudo /opt/splunk/bin/splunk start --accept-license, I observed that Splunk successfully migrated the configuration and settings in etc to be compatible with 9.2.7.&lt;BR /&gt;* I now have a fully functional Splunk v9.2.7 instance with all historical indexed data present&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2025 11:57:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749179#M22560</guid>
      <dc:creator>venksel</dc:creator>
      <dc:date>2025-07-03T11:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749180#M22561</link>
      <description>&lt;P&gt;As I said before - move an upgrade in one move was risky.&lt;/P&gt;&lt;P&gt;I don't see the point in uninstalling and reinstalling the package.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2025 12:11:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749180#M22561</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-07-03T12:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749182#M22562</link>
      <description>&lt;P&gt;I can share the log file from the migration, however, i don't see an option here to upload. PLease do you know if there a&amp;nbsp; way to share/upload log files.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2025 12:38:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749182#M22562</guid>
      <dc:creator>venksel</dc:creator>
      <dc:date>2025-07-03T12:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749226#M22568</link>
      <description>Here is link to repository which you could use to download older splunk versions &lt;A href="https://github.com/ryanadler/downloadSplunk/tree/main" target="_blank"&gt;https://github.com/ryanadler/downloadSplunk/tree/main&lt;/A&gt;</description>
      <pubDate>Thu, 03 Jul 2025 21:37:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749226#M22568</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-07-03T21:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749229#M22569</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;, don’t move and upgrade at same time! Also you shouldn’t upgrade directly from 8.2.x to 9.2.x. Only supported way is migrate over one version like 8.2-&amp;gt; 9.0 -&amp;gt; 9.2 etc. and you must start your node(s) after upgrade to each separate versions.&lt;/P&gt;&lt;P&gt;Splunk doesn’t support rollback of version upgrade. So uninstall version is not needed/suggested.&lt;/P&gt;&lt;P&gt;Also you should check in Amz23 at least systemd startup settings as those are somehow different than in RHEL. Cgroups default is v2 which needs some parameter changes etc. Also if your environment needs IMDS its version has changed to v2. Probably doesn’t affect to you unless yo are using some old AWS ta?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jul 2025 21:54:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749229#M22569</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-07-03T21:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749274#M22579</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Agreed, however, when i start the Splunk after accepting the license agreement, i run into the following screenshot which takes care of the seamless migration, I believe what I'm doing must be a documented procedure and nothing unusual and it also creates a migration logs with the details of what was done during the process... please lemme know your thoughts!!&lt;BR /&gt;&lt;BR /&gt;Thanks for your help &amp;amp; Happy 4th!!&lt;BR /&gt;&lt;BR /&gt;Download migration log from here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://limewire.com/d/Jd4GD#NEdMoeWwVg" target="_blank" rel="noopener"&gt;https://limewire.com/d/Jd4GD#NEdMoeWwVg&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="venksel1_0-1751671605628.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39573iC73FD581950BAC40/image-size/medium?v=v2&amp;amp;px=400" role="button" title="venksel1_0-1751671605628.png" alt="venksel1_0-1751671605628.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jul 2025 23:38:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749274#M22579</guid>
      <dc:creator>venksel1</dc:creator>
      <dc:date>2025-07-04T23:38:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749301#M22582</link>
      <description>&lt;P&gt;There are several things which "work" but which are unsupported and might bite you here and there at some point. Just saying. As&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;pointed out (I admit I didn't bother to check this one), straight jump to 9.2 from your old version isn't supported so whilie the migration seems to have gone well, you might have skipped some step normally performed on migration to 9.0, for example, which later versions might rely on.&lt;/P&gt;&lt;P&gt;Again - you might get away with doing unsupported things if you're lucky. But you might not. And debugging will be more difficult later if you have some issues lingering from a few versions back.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 08:51:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749301#M22582</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-07-07T08:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Migration from RHEL to AL2023</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749310#M22584</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231884"&gt;@PickleRick&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for taking time to reply. Much appreciated. I'd prefer to take the upgrade path of 8.2-&amp;gt;9.0.x -&amp;gt; 9.2.7; unfortunately, 9.0 does not support AL2023.&lt;/P&gt;&lt;P&gt;Please take a moment to review the migration log file as didn't see any alarming (you may download from the link below), i did disable THP and verified the ulimits to match the recommended settings.&lt;/P&gt;&lt;P&gt;&lt;A href="https://limewire.com/d/PDWiS#NfyxSpwkrX" target="_blank" rel="noopener"&gt;https://limewire.com/d/PDWiS#NfyxSpwkrX&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also,&amp;nbsp; log ingestion is working properly . It's been a week since I upgraded our test instance of Splunk to 9.27 and there has been no issues. The health stats from Settings-&amp;gt;Monitoring Console reports no issues. And we dont use workload management feature in Splunk from a cgroup compatibility standpoint we are covered...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="venksel_0-1751892995513.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39580i431A7A98A7196DB0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="venksel_0-1751892995513.png" alt="venksel_0-1751892995513.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;With regards to SystemD, it was setup using the below commands in AL2023:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sudo /opt/splunk/bin/splunk enable boot-start -user splunk -systemd-managed 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sudo systemctl daemon-reload&lt;/P&gt;&lt;P&gt;sudo systemctl start splunkd&lt;/P&gt;&lt;P&gt;sudo systemctl enable splunkd&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 13:59:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-Migration-from-RHEL-to-AL2023/m-p/749310#M22584</guid>
      <dc:creator>venksel</dc:creator>
      <dc:date>2025-07-07T13:59:34Z</dc:date>
    </item>
  </channel>
</rss>

