<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrating Splunk Enterprise Security from VM to new physical host in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-migrate-Splunk-Enterprise-Security-from-VM-to-new/m-p/640422#M11461</link>
    <description>&lt;P&gt;Have you considered fresh ES install on the new physical server and migrate the data from your VM?&lt;/P&gt;</description>
    <pubDate>Tue, 18 Apr 2023 20:02:43 GMT</pubDate>
    <dc:creator>lakshman239</dc:creator>
    <dc:date>2023-04-18T20:02:43Z</dc:date>
    <item>
      <title>How to migrate Splunk Enterprise Security from VM to new physical host?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-migrate-Splunk-Enterprise-Security-from-VM-to-new/m-p/632221#M11332</link>
      <description>&lt;P&gt;I need to migrate my current ES installation from a VM to a physical host, due to performance issues in the virtual instance.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because of internal policies, I cannot simply clone the system via rsync, as the new physical box must have a new name to indicate it isn't a VM.&lt;/P&gt;
&lt;P&gt;I tried copying the /opt/splunk/etc/system subdirectory of the new server to a backup location, then using rsync to replicate the /opt/splunk/etc subdirectory structure from the functional VM to the new server. I copied the backup of system back into place, except for the server.conf which I merged the two together.&lt;/P&gt;
&lt;P&gt;Tons of errors. Tons of missing data in the ES dashboards.&lt;/P&gt;
&lt;P&gt;What am I missing?&lt;/P&gt;
&lt;P&gt;Thanks in advance for any suggestions.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 21:03:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-migrate-Splunk-Enterprise-Security-from-VM-to-new/m-p/632221#M11332</guid>
      <dc:creator>discenzadoe</dc:creator>
      <dc:date>2023-04-19T21:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating Splunk Enterprise Security from VM to new physical host</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-migrate-Splunk-Enterprise-Security-from-VM-to-new/m-p/640422#M11461</link>
      <description>&lt;P&gt;Have you considered fresh ES install on the new physical server and migrate the data from your VM?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 20:02:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-migrate-Splunk-Enterprise-Security-from-VM-to-new/m-p/640422#M11461</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2023-04-18T20:02:43Z</dc:date>
    </item>
  </channel>
</rss>

