Alerting

What is the best way to transfer reports and alerts from one search head to another search head?

packet_hunter
Contributor

I have about 50 reports saved on a search head that is being decommissioned.

Do I have to manually copy the alerts and reports or is there a way to export them from a file and import them to the new search head?

Thank you

Tags (3)
0 Karma
1 Solution

MuS
Legend

Hi packet_hunter,

there is a doc about migrating to a search head cluster http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Migratefromsearchheadpooling#Migrate_t... which provides all steps you need to do - ignore step 4 & 5 in your case.

Another approach is to create an App and move your searches into this app (make sure they are not private), export/package the app http://docs.splunk.com/Documentation/Splunk/latest/Admin/CLIadmincommands#Commands.2C_objects.2C_and... , and install it on the new search head.

Hope this helps ...

cheers, MuS

View solution in original post

0 Karma

MuS
Legend

Hi packet_hunter,

there is a doc about migrating to a search head cluster http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Migratefromsearchheadpooling#Migrate_t... which provides all steps you need to do - ignore step 4 & 5 in your case.

Another approach is to create an App and move your searches into this app (make sure they are not private), export/package the app http://docs.splunk.com/Documentation/Splunk/latest/Admin/CLIadmincommands#Commands.2C_objects.2C_and... , and install it on the new search head.

Hope this helps ...

cheers, MuS

0 Karma

packet_hunter
Contributor

Thank you !

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...