Deployment Architecture

Splunk Migration from existing server to a new server



I have a requirement to upgrade RHEL from version 7.9 to 8.X, and our infrastructure team is currently in the process of building a new set of servers running on RHEL 8.X. Consequently, I will need to migrate Splunk from the existing RHEL OS 7.9 to 8.X.

Our Splunk architecture is on-premise and includes multiple Search Heads (SHs) in a cluster, Indexers in a cluster, and various other components.

Has anyone here performed a migration from one OS to another version of the same OS before? Could I please get some guidelines on how to perform this, especially concerning clustered components?


I have checked the below steps:

  • Stop Splunk Enterprise services
  • Copy the entire contents of the $SPLUNK_HOME directory from the old host to the new host.
  • Install Splunk Enterprise on the new host.
  • Start Splunk Enterprise on the new instance.

and specifically looking for the any additional steps that need to be performed, particularly for clustered components.

Thank you.


Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...