<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Migration instructions from single install to distributed? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417472#M14908</link>
    <description>&lt;P&gt;Hi&lt;BR /&gt;
I have a single install (Everything on one machine).&lt;/P&gt;

&lt;P&gt;I want to go to one search head and 2 indexers (non clustered) multiple machines.&lt;/P&gt;

&lt;P&gt;Is there a set of instruction on how to do this, the doc is great but there seem to be so many options that I get lost.&lt;BR /&gt;
I am looking for step 1 2, 3..etc...&lt;/P&gt;

&lt;P&gt;I also have a question like:&lt;BR /&gt;
If I change the current install from SH+Indexer -&amp;gt; indexer and create a separate search head(I think this is the best way), &lt;BR /&gt;
do I have to reinstall all my apps onto the new search head?&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Robert&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jun 2019 15:27:36 GMT</pubDate>
    <dc:creator>robertlynch2020</dc:creator>
    <dc:date>2019-06-10T15:27:36Z</dc:date>
    <item>
      <title>Migration instructions from single install to distributed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417472#M14908</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;
I have a single install (Everything on one machine).&lt;/P&gt;

&lt;P&gt;I want to go to one search head and 2 indexers (non clustered) multiple machines.&lt;/P&gt;

&lt;P&gt;Is there a set of instruction on how to do this, the doc is great but there seem to be so many options that I get lost.&lt;BR /&gt;
I am looking for step 1 2, 3..etc...&lt;/P&gt;

&lt;P&gt;I also have a question like:&lt;BR /&gt;
If I change the current install from SH+Indexer -&amp;gt; indexer and create a separate search head(I think this is the best way), &lt;BR /&gt;
do I have to reinstall all my apps onto the new search head?&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Robert&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 15:27:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417472#M14908</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2019-06-10T15:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Migration instructions from single install to distributed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417473#M14909</link>
      <description>&lt;P&gt;Hi Robert,&lt;/P&gt;

&lt;P&gt;There are plenty of Splunk documents on how to setup a distributed configuration (which you've probably encountered already):&lt;BR /&gt;
New install: &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/DistSearch/Overviewofconfiguration"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/DistSearch/Overviewofconfiguration&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;However, Google isn't really providing insight when migrating from a standalone to a distributed environment.&lt;/P&gt;

&lt;P&gt;I think the easiest path would be as follows:&lt;BR /&gt;
1. Install new Splunk instance (this will be the search head)&lt;BR /&gt;
Linux: &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Installation/InstallonLinux"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.0/Installation/InstallonLinux&lt;/A&gt;&lt;BR /&gt;
Windows: &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Installation/ChoosetheuserSplunkshouldrunas"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.0/Installation/ChoosetheuserSplunkshouldrunas&lt;/A&gt;&lt;BR /&gt;
2. Configure it to send data to the old instance/indexer-to-be&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/DistSearch/Forwardsearchheaddata"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/DistSearch/Forwardsearchheaddata&lt;/A&gt;&lt;BR /&gt;
3. Configure it to use the old instance/indexer-to-be as a search-peer (same thing as indexer, different terminology)&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/DistSearch/Configuredistributedsearch"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/DistSearch/Configuredistributedsearch&lt;/A&gt;&lt;BR /&gt;
4. Copy your apps from the old instance to the new search head (/opt/splunk/etc/apps)&lt;BR /&gt;
App migration reference: &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Migratefromstandalonesearchheads"&gt;https://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Migratefromstandalonesearchheads&lt;/A&gt;&lt;BR /&gt;
6. Restart your search head&lt;BR /&gt;
7. Review .conf files in /opt/splunk/etc/system/local to determine what needs to be moved to the search head&lt;/P&gt;

&lt;P&gt;That's a rough overview, but should get you to where you want to be.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 19:23:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417473#M14909</guid>
      <dc:creator>jnudell_2</dc:creator>
      <dc:date>2019-06-10T19:23:52Z</dc:date>
    </item>
    <item>
      <title>Re: Migration instructions from single install to distributed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417474#M14910</link>
      <description>&lt;P&gt;If it was as easy as 1,2,3 the docs would say so.  The docs have a lot of options because there are a lot of variables.&lt;/P&gt;

&lt;P&gt;If I was in your shoes, I'd make the existing server an indexer and add new servers to act as search head and second indexer.  Usually, it's not necessary to re-install apps - just transfer $SPLUNK_HOME/etc/apps from the old server to the new one.  There are caveats so read the docs.&lt;BR /&gt;
The second indexer will start out empty, but will accumulate data over time.  Until then, however, searches won't benefit from the second indexer.  Better is to cluster the indexes and balance the indexes from the start, but that's something for Professional Services to handle for you.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2019 19:33:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417474#M14910</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-06-10T19:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: Migration instructions from single install to distributed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417475#M14911</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Thanks for this, i will try it and get back&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jun 2019 16:03:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417475#M14911</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2019-06-12T16:03:23Z</dc:date>
    </item>
    <item>
      <title>Re: Migration instructions from single install to distributed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417476#M14912</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Thanks for this answer.&lt;BR /&gt;
We have done the following. One new search head and 2 indexers. The 1st Indexer is the old production, but when we start it up all the datamodels start to rebuild. Is there a way to get the datamodels not to rebuild?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Robert&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 13:44:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417476#M14912</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2019-10-09T13:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Migration instructions from single install to distributed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417477#M14913</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;Thanks for this answer.&lt;BR /&gt;
We have done the following. One new search head and 2 indexers. The 1st Indexer is the old production, but when we start it up all the datamodels start to rebuild. Is there a way to get the datamodels not to rebuild?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Robert&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 14:00:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417477#M14913</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2019-10-09T14:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: Migration instructions from single install to distributed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417478#M14914</link>
      <description>&lt;P&gt;Do not use Windows for your infrastructure here.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2019 14:00:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417478#M14914</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-10-09T14:00:23Z</dc:date>
    </item>
    <item>
      <title>Re: Migration instructions from single install to distributed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417479#M14915</link>
      <description>&lt;P&gt;noted we are on UNIX for everything&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 11:13:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417479#M14915</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2019-10-11T11:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Migration instructions from single install to distributed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417480#M14916</link>
      <description>&lt;P&gt;You have saved yourself much avoidable pain.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 12:56:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417480#M14916</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-10-11T12:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Migration instructions from single install to distributed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417481#M14917</link>
      <description>&lt;P&gt;If you are going to use them, they must be rebuilt.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 12:57:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417481#M14917</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-10-11T12:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Migration instructions from single install to distributed?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417482#M14918</link>
      <description>&lt;P&gt;Ok thanks - that is disappointing to here, it looks like the migration process will take ~48 hour of MAX CPU on a 60 core machine.&lt;/P&gt;

&lt;P&gt;We have ~20 Data models. &lt;/P&gt;

&lt;P&gt;Lucky we are on a very very good machine, otherwise we would have to stop production or do a parallel run&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 14:04:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Migration-instructions-from-single-install-to-distributed/m-p/417482#M14918</guid>
      <dc:creator>robertlynch2020</dc:creator>
      <dc:date>2019-10-11T14:04:03Z</dc:date>
    </item>
  </channel>
</rss>

