Deployment Architecture

How to migrate Heavy Forwarder from Windows server to Linux Server

Jagadeesh2022
Path Finder

Hi All,

Currently we are using 3 Heavy Forwarder in Windows server. Due to budget problem we are planning to move all HF to Linux server. 

Kindly guide and suggest how to move HF from Windows to Linux. 

How to copy to already installed apps and existing settings and configuration files from windows to Linux?

Thank in advance for your reply.

 

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Splunk config files and most apps are platform-agnostic.  The files can be copied directly from %SPLUNK_HOME%/etc/system to $SPLUNK_HOME/etc/system and from %SPLUNK_HOME%/etc/apps to $SPLUNK_HOME/etc/apps.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @Jagadeesh2022,

as @richgalloway said, you can use the same configurations passing from Windows to Linux, you have only to put attention on to issues:

  • if you have to read local files, you have to change the path ("/" instead of "\") of the files to read,
  • you need of TA-Linux instead TA-Windows to monitor the machine. 

One addition information: You said that you have to change for budget reasons, in general, I hint to use Linux instead Windows in all the servers to run Splunk: I never saw large Splunk production infrastructures using Windows!

Ciao.

Giuseppe

Jagadeesh2022
Path Finder

Thank you @gcusello 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk config files and most apps are platform-agnostic.  The files can be copied directly from %SPLUNK_HOME%/etc/system to $SPLUNK_HOME/etc/system and from %SPLUNK_HOME%/etc/apps to $SPLUNK_HOME/etc/apps.

---
If this reply helps you, Karma would be appreciated.

Jagadeesh2022
Path Finder

Thank you @richgalloway 

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...