<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it the best practice to import savedsearches.conf across multiple Splunk instances? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Is-it-the-best-practice-to-import-savedsearches-conf-across/m-p/255899#M76632</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I am new to Splunk and was looking for tutorials regarding Searching and Reporting on Splunk.&lt;/P&gt;

&lt;P&gt;My question here is when we write Splunk queries and save those reports it gets saved to savedsearches.conf file. For my continuous deployment across different environments (dev,qa), we need a mechanism to import and run these queries on different Splunk instances.&lt;/P&gt;

&lt;P&gt;Did some searching and found I could import/copy these savedsearches.conf to different instances and can see the reports/alerts  created on host one is also coming up on host 2. Just want to know if this would be correct process to import all configuration across multiple Splunk servers?&lt;/P&gt;

&lt;P&gt;Do any other processes need to be met for the above requirement? Please share the documentation, if so.&lt;/P&gt;</description>
    <pubDate>Mon, 05 Dec 2016 20:49:56 GMT</pubDate>
    <dc:creator>chitralekha</dc:creator>
    <dc:date>2016-12-05T20:49:56Z</dc:date>
    <item>
      <title>Is it the best practice to import savedsearches.conf across multiple Splunk instances?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-the-best-practice-to-import-savedsearches-conf-across/m-p/255899#M76632</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I am new to Splunk and was looking for tutorials regarding Searching and Reporting on Splunk.&lt;/P&gt;

&lt;P&gt;My question here is when we write Splunk queries and save those reports it gets saved to savedsearches.conf file. For my continuous deployment across different environments (dev,qa), we need a mechanism to import and run these queries on different Splunk instances.&lt;/P&gt;

&lt;P&gt;Did some searching and found I could import/copy these savedsearches.conf to different instances and can see the reports/alerts  created on host one is also coming up on host 2. Just want to know if this would be correct process to import all configuration across multiple Splunk servers?&lt;/P&gt;

&lt;P&gt;Do any other processes need to be met for the above requirement? Please share the documentation, if so.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 20:49:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-the-best-practice-to-import-savedsearches-conf-across/m-p/255899#M76632</guid>
      <dc:creator>chitralekha</dc:creator>
      <dc:date>2016-12-05T20:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Is it the best practice to import savedsearches.conf across multiple Splunk instances?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-the-best-practice-to-import-savedsearches-conf-across/m-p/255900#M76633</link>
      <description>&lt;P&gt;The closest article I can find to this is &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1/DistSearch/Migratefromstandalonesearchheads"&gt;Migrate from a standalone search head to a search head cluster&lt;/A&gt; &lt;/P&gt;

&lt;P&gt;I would keep in mind that anything private is going under the etc/users directory, anything shared is under the etc/apps/ directory.&lt;BR /&gt;
The &lt;EM&gt;metadata&lt;/EM&gt; is also important in addition to the savedsearches.conf depending on what export settings you intend to use, I have moved searches around before and lost the owner/permissions on them by not including the metadata file...these are metdata/local.meta and metadata/default.meta in the relevant app directory...&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 00:02:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-the-best-practice-to-import-savedsearches-conf-across/m-p/255900#M76633</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2016-12-06T00:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Is it the best practice to import savedsearches.conf across multiple Splunk instances?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Is-it-the-best-practice-to-import-savedsearches-conf-across/m-p/255901#M76634</link>
      <description>&lt;P&gt;thanks for mentioning about the meta data. So If we are saving any thing with app permission we should keep in mind migrating all the configuration present in $splunk_home/etc/apps/&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 00:24:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Is-it-the-best-practice-to-import-savedsearches-conf-across/m-p/255901#M76634</guid>
      <dc:creator>chitralekha</dc:creator>
      <dc:date>2016-12-06T00:24:52Z</dc:date>
    </item>
  </channel>
</rss>

