<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrating Heavy Forwarder to a new server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Migrating-Heavy-Forwarder-to-a-new-server/m-p/691476#M115013</link>
    <description>&lt;P&gt;Did this work? Did you discover that you had to implement additional steps to make it work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Farhan&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jun 2024 17:21:29 GMT</pubDate>
    <dc:creator>fahmed11</dc:creator>
    <dc:date>2024-06-24T17:21:29Z</dc:date>
    <item>
      <title>Migrating Heavy Forwarder to a new server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Migrating-Heavy-Forwarder-to-a-new-server/m-p/513044#M86995</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I have inherited a HF running on a Linux server collecting data from several cloud sources using the inputs from below TAs, that need to be moved to a newly built Linux server (no Splunk version upgrades).&lt;/P&gt;&lt;P&gt;azure_event_hub&lt;BR /&gt;azure_security_center_input&lt;BR /&gt;digital_shadows_searchlight&lt;BR /&gt;microsoft_graph_security&lt;BR /&gt;MS_AAD_audit&lt;BR /&gt;MS_AAD_signins&lt;BR /&gt;mscs_azure_audit&lt;BR /&gt;mscs_azure_resource&lt;BR /&gt;splunk_ta_o365_management_activity&lt;BR /&gt;windows_defender_atp_alerts&lt;/P&gt;&lt;P&gt;Can you please recommend any procedures and best practices to make sure there is no data duplication ?&lt;/P&gt;&lt;P&gt;Thinking of the below ways, will any of these work and which is better ?&lt;/P&gt;&lt;P&gt;1.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; a. Stop Splunk on old host and copy Splunk directory to new host.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; b. Change the splunk server/instance name to match the new host.&lt;BR /&gt;&amp;nbsp; &amp;nbsp; c. Start splunk on the new host.&lt;/P&gt;&lt;P&gt;2. Install fresh Splunk on new host, and configure TAs, is there a way to move any checkpoints (or something similar to fishbuckets ? ) from the old HF, so that the TAs pull data from where it was stopped on the existing HF ?&lt;/P&gt;&lt;P&gt;Thanks a lot in advance&lt;/P&gt;&lt;P&gt;Chaith&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 16:19:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Migrating-Heavy-Forwarder-to-a-new-server/m-p/513044#M86995</guid>
      <dc:creator>cnuguri_ncc</dc:creator>
      <dc:date>2020-08-07T16:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating Heavy Forwarder to a new server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Migrating-Heavy-Forwarder-to-a-new-server/m-p/513048#M86996</link>
      <description>&lt;P&gt;Best way is to move Splunk app on HF since you have checkpoints for modular inputs.&lt;/P&gt;&lt;P&gt;stop splunk on old instance.&lt;/P&gt;&lt;P&gt;create same splunk user which is used on existing server on new server.&lt;/P&gt;&lt;P&gt;just copy $SPLUNK_HOME to new splunk instance&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;and change instance name and hostname in&amp;nbsp;&lt;/P&gt;&lt;P&gt;system/local/server.conf and inkuts.conf if you are going to have new hostname to new server you have configured. You can continue using same hostname if you are decommissioning existing HF.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then start splunk on new instance.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 16:56:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Migrating-Heavy-Forwarder-to-a-new-server/m-p/513048#M86996</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-07T16:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating Heavy Forwarder to a new server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Migrating-Heavy-Forwarder-to-a-new-server/m-p/513266#M87047</link>
      <description>&lt;P&gt;Thanks a lot !&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 08:15:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Migrating-Heavy-Forwarder-to-a-new-server/m-p/513266#M87047</guid>
      <dc:creator>cnuguri_ncc</dc:creator>
      <dc:date>2020-08-10T08:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating Heavy Forwarder to a new server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Migrating-Heavy-Forwarder-to-a-new-server/m-p/513358#M87057</link>
      <description>&lt;P&gt;Great. You are welcome.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 14:18:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Migrating-Heavy-Forwarder-to-a-new-server/m-p/513358#M87057</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-10T14:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating Heavy Forwarder to a new server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Migrating-Heavy-Forwarder-to-a-new-server/m-p/691476#M115013</link>
      <description>&lt;P&gt;Did this work? Did you discover that you had to implement additional steps to make it work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Farhan&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 17:21:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Migrating-Heavy-Forwarder-to-a-new-server/m-p/691476#M115013</guid>
      <dc:creator>fahmed11</dc:creator>
      <dc:date>2024-06-24T17:21:29Z</dc:date>
    </item>
  </channel>
</rss>

