Deployment Architecture

Is it possible to merge two search clusters?

lianwan
Explorer

We have 2 separate search clusters fed by the same index cluster.
The reason to have two search clusters was to host 2 sets of apps/add-ons that serve 2 different functional groups.

Now we are thinking about making one big search group. We'd like to migrate all apps/add-ons, reports, dashboards etc. from 2 old clusters to the new one. Both old clusters use the same LDAP server.

Anybody with similar experience?

0 Karma
1 Solution

yannK
Splunk Employee
Splunk Employee

There is no magic process to merge 2 SH, or 2 SHC.
You will have to do some manual merging of apps/configs/users/profiles/dashboard/datamodels..
If all your apps are different, it's probably easier, but if the same app existed on the 2 locations, you may have to go down to the /local and /lookups folders and selectively merge the conf files (and resolve dupes stanza)

For datamodels, if you had 2 identical ones with acceleration, you can only keep one of them.

View solution in original post

0 Karma

gjanders
SplunkTrust
SplunkTrust

I have scripts such as transferknowledgeobjects.py in https://github.com/gjanders/Splunk which might help move knowledge objects around but merging 2 search head (or clusters) will still take quite a bit of work...

0 Karma

yannK
Splunk Employee
Splunk Employee

There is no magic process to merge 2 SH, or 2 SHC.
You will have to do some manual merging of apps/configs/users/profiles/dashboard/datamodels..
If all your apps are different, it's probably easier, but if the same app existed on the 2 locations, you may have to go down to the /local and /lookups folders and selectively merge the conf files (and resolve dupes stanza)

For datamodels, if you had 2 identical ones with acceleration, you can only keep one of them.

0 Karma

xavierashe
Contributor

We have a similar setup. One SHC for Security, one for everyone else. If you have Enterprise Security or ITSI, I suggest you keep them separate.

The things you might run into is Knowledge Objects like lookups with the same name.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...

Edge Processor Scaling, Energy & Manufacturing Use Cases, and More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Get More Out of Your Security Practice With a SIEM

Get More Out of Your Security Practice With a SIEMWednesday, July 31, 2024  |  11AM PT / 2PM ETREGISTER ...