<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Moving Splunk from one computer to another in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47581#M757</link>
    <description>&lt;P&gt;Maybe I just misunderstood you. As long as you defined the paths in your configurations, and you include in your zip all of the contents inside your $SPLUNK_HOME, then all configuration files will move along with your splunk installation. Therefore pointing to the same places that your old server was pointing to, no matter what type of splunk you are porting.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Sep 2012 13:44:38 GMT</pubDate>
    <dc:creator>aholzer</dc:creator>
    <dc:date>2012-09-14T13:44:38Z</dc:date>
    <item>
      <title>Moving Splunk from one computer to another</title>
      <link>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47575#M751</link>
      <description>&lt;P&gt;Can you point me in the right direction.&lt;BR /&gt;
My existing database must be retained on migration to another machine.&lt;BR /&gt;
I am running 4.2.2 on Max OSX Lion&lt;/P&gt;

&lt;P&gt;Cheers,&lt;/P&gt;

&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2011 06:52:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47575#M751</guid>
      <dc:creator>profileaudio</dc:creator>
      <dc:date>2011-07-23T06:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Splunk from one computer to another</title>
      <link>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47576#M752</link>
      <description>&lt;P&gt;&lt;A href="http://www.splunk.com/wiki/Deploy:Migrating_a_Splunk_Install"&gt;http://www.splunk.com/wiki/Deploy:Migrating_a_Splunk_Install&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2011 20:34:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47576#M752</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2011-07-23T20:34:13Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Splunk from one computer to another</title>
      <link>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47577#M753</link>
      <description>&lt;P&gt;This is a bad guide. It only contains tips, but it doesn't say anywhere which directories should be moved.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2012 11:09:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47577#M753</guid>
      <dc:creator>HXCaine</dc:creator>
      <dc:date>2012-09-14T11:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Splunk from one computer to another</title>
      <link>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47578#M754</link>
      <description>&lt;P&gt;The easiest way to do it would be as follows:&lt;BR /&gt;
1) run ./$SPLUNK_HOME/bin/splunk stop&lt;BR /&gt;
2) Find your indexes.conf where you define where to save your indexes (could be in etc/apps, or etc/system/local). Zip all the db related files that you find in the directories defined in your indexes.conf.&lt;BR /&gt;
3) Zip your $SPLUNK_HOME directory.&lt;BR /&gt;
4) Port over both zips to the new box, and unzip them.&lt;BR /&gt;
5) Make sure you run a search for any metadata files containing the name / ip of the old server.&lt;BR /&gt;
6) run ./$SPLUNK_HOME/bin/splunk start.&lt;/P&gt;

&lt;P&gt;I used this method to upgrade a number of forwarders to include certain basic configurations, and to port over the databases from one location in a shared drive, to a different one.&lt;/P&gt;

&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:26:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47578#M754</guid>
      <dc:creator>aholzer</dc:creator>
      <dc:date>2020-09-28T12:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Splunk from one computer to another</title>
      <link>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47579#M755</link>
      <description>&lt;P&gt;What about hard-coded paths? E.g. for directory data inputs&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2012 13:31:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47579#M755</guid>
      <dc:creator>HXCaine</dc:creator>
      <dc:date>2012-09-14T13:31:11Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Splunk from one computer to another</title>
      <link>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47580#M756</link>
      <description>&lt;P&gt;I thought you were talking about an indexer (hence your database question). If you are talking about a forwarder then yes, you will have to update the monitoring path inside of the inputs.conf file, unless of course your new machine has the exact same directory structure.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2012 13:40:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47580#M756</guid>
      <dc:creator>aholzer</dc:creator>
      <dc:date>2012-09-14T13:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Splunk from one computer to another</title>
      <link>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47581#M757</link>
      <description>&lt;P&gt;Maybe I just misunderstood you. As long as you defined the paths in your configurations, and you include in your zip all of the contents inside your $SPLUNK_HOME, then all configuration files will move along with your splunk installation. Therefore pointing to the same places that your old server was pointing to, no matter what type of splunk you are porting.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2012 13:44:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47581#M757</guid>
      <dc:creator>aholzer</dc:creator>
      <dc:date>2012-09-14T13:44:38Z</dc:date>
    </item>
    <item>
      <title>Re: Moving Splunk from one computer to another</title>
      <link>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47582#M758</link>
      <description>&lt;P&gt;If you are on windows to windows (32bit to 64 or 64bit to 64bit)&lt;/P&gt;

&lt;P&gt;Here are the steps :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Stop the old instance, stop the new instance&lt;/LI&gt;
&lt;LI&gt;redirect the forwarder to the new instance (or not if you use the same ip/uri)&lt;/LI&gt;
&lt;LI&gt;backup the full &lt;CODE&gt;$SPLUNK_HOME\etc\folder&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;move to the equivalent folder
the auth and ssh keys : &lt;CODE&gt;$SPLUNK_HOME\etc\auth&lt;/CODE&gt; (that also contains the secret key for password encryption)
the user password : &lt;CODE&gt;$SPLUNK_HOME\etc\passwd&lt;/CODE&gt;
the apps &lt;CODE&gt;$SPLUNK_HOME\etc\apps\&lt;/CODE&gt;
the local configuration &lt;CODE&gt;$SPLUNK_HOME\etc\system\local&lt;/CODE&gt;
( eventually modify the server.conf  and inputs.conf from ...\etc\system\local that contain the hold hostname )
the users folders&lt;CODE&gt;$SPLUNK_HOME\etc\users&lt;/CODE&gt;&lt;/LI&gt;
&lt;LI&gt;on the original move the indexes
check in indexes.conf to see the path of all your indexes, the default is using a dynamic path  &lt;CODE&gt;$SPLUNK_HOME\var\lib\splunk\&lt;/CODE&gt;&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;If they are hard coded as &lt;CODE&gt;c:\program files\splunk\var\lib\splunk\...&lt;/CODE&gt; then change them to the new location &lt;BR /&gt;
- double check the permissions on the files. &lt;BR /&gt;
- restart the new indexer and verify that all is working, and searchable&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2012 22:34:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Moving-Splunk-from-one-computer-to-another/m-p/47582#M758</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-10-22T22:34:36Z</dc:date>
    </item>
  </channel>
</rss>

