Deployment Architecture

Splunk Migration: From ESXI to Hyper-V

0xAli
Explorer

Hi,

We want to migrate from the ESXI VM to the Hyper-V:

Our Initial approach:

Fresh OS + Splunk installations on Hyper-V, then migrate Splunk configurations from the existing environment.

Migrate 5 Splunk VMs:

  • Universal Forwarder 01
  • Universal Forwarder 02
  • Heavy Forwarder 01
  • Cluster Master
  • Deployment Serve



what is the best practice or recommendation for that migration.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @0xAli 

Are you maintaining the same IP/hostname configuration on HyperV? This might make a big difference.

The Cluster Manager is pretty stateless so apart from copying over the manager-apps there shouldnt be too much to do. The Deployment Server is obviously going to need to be in place before the forwarders are brought online but for me the thing you will need to make sure is that the forwarders have all the relevant configs they need *before* they are accessible from their clients, otherwise they might receive data and not process it correctly.  I guess the easiest way to do this is make sure the inputs.conf configuration is distributed from the DS, therefore it wont be listening until its downloaded its apps from the DS and updated etc.

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...