<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best practices when migrating a Windows search head to new physical hardware in an indexer clustering environment? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Best-practices-when-migrating-a-Windows-search-head-to-new/m-p/263566#M50589</link>
    <description>&lt;P&gt;As of Splunk Enterprise 6.3, search head clustering is supported on Windows.&lt;/P&gt;

&lt;P&gt;You can get away with copying over all the files. Then just edit &lt;CODE&gt;$SPLUNK_HOME\etc\system\local\server.conf&lt;/CODE&gt;&lt;BR /&gt;
with the updated server information and restart Splunk.&lt;/P&gt;

&lt;P&gt;Just don't toss the old search head until you are sure the new one works! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Feb 2016 19:13:26 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2016-02-02T19:13:26Z</dc:date>
    <item>
      <title>Best practices when migrating a Windows search head to new physical hardware in an indexer clustering environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-practices-when-migrating-a-Windows-search-head-to-new/m-p/263565#M50588</link>
      <description>&lt;P&gt;I suppose this is a multi-question post.&lt;/P&gt;

&lt;P&gt;We have a clustered environment and are replacing the hardware our search head lives on currently. We have 1 search head, 2 indexers (clustered), and a deployment server/cluster master/license master all in one. Our environment is entirely Windows and last I checked, Search head clustering on Windows is not an option.&lt;/P&gt;

&lt;P&gt;The new box will have a new IP and a new hostname.&lt;/P&gt;

&lt;P&gt;My question is: Has anyone done this in the past? If so, is it as simple as transferring all of the Splunk files ( &lt;CODE&gt;d:\program files\splunk\*.*&lt;/CODE&gt;) to the new box? Or is there a subset of files/directories that I can simply transfer (user's/searches/stuff like that).&lt;/P&gt;

&lt;P&gt;The issue I see standing out is obviously the name change, and probably why transferring all files over would be a bad idea &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2016 18:01:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-practices-when-migrating-a-Windows-search-head-to-new/m-p/263565#M50588</guid>
      <dc:creator>hagjos43</dc:creator>
      <dc:date>2016-02-02T18:01:45Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices when migrating a Windows search head to new physical hardware in an indexer clustering environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-practices-when-migrating-a-Windows-search-head-to-new/m-p/263566#M50589</link>
      <description>&lt;P&gt;As of Splunk Enterprise 6.3, search head clustering is supported on Windows.&lt;/P&gt;

&lt;P&gt;You can get away with copying over all the files. Then just edit &lt;CODE&gt;$SPLUNK_HOME\etc\system\local\server.conf&lt;/CODE&gt;&lt;BR /&gt;
with the updated server information and restart Splunk.&lt;/P&gt;

&lt;P&gt;Just don't toss the old search head until you are sure the new one works! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2016 19:13:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-practices-when-migrating-a-Windows-search-head-to-new/m-p/263566#M50589</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2016-02-02T19:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: Best practices when migrating a Windows search head to new physical hardware in an indexer clustering environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-practices-when-migrating-a-Windows-search-head-to-new/m-p/263567#M50590</link>
      <description>&lt;P&gt;Thanks so much!&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2016 19:19:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-practices-when-migrating-a-Windows-search-head-to-new/m-p/263567#M50590</guid>
      <dc:creator>hagjos43</dc:creator>
      <dc:date>2016-02-02T19:19:08Z</dc:date>
    </item>
  </channel>
</rss>

