Getting Data In

Upgrading a splunk server hardware

freeborn
Explorer

We are in the process of upgrading our splunk server hardware and I was looking for some sort of best practice. I am hoping to keep everything the same in the new server (ip, name ect ect) So it is more of a clone that I am looking to do.

Any feed back would be appreciated.

MuS
Legend

Hi freeborn

as long as the OS stays the same, meaning during your hardware update you will not change the OS, it is more a matter of how to clone the OS and data.

If you setup both servers (old and new in parallel) Splunk itself can be moved/cloned/migrated onto new hardware, read more about this in the Migrating a Splunk Install wiki.

Here is the link http://wiki.splunk.com/Deploy:Migrating_a_Splunk_Install

hope this helps.....

cheers,

MuS

dale_lakes8769
Explorer

Your link is missing one 'l'. Correct link is http://wiki.splunk.com/Deploy:Migrating_a_Splunk_Install

0 Karma

MuS
Legend

Thanks for the hint @dale.lakes8769 !
I had to add a line break after the link otherwise the second l is being cut off - very strange ?!? Anyway added the link as well.

0 Karma

wrangler2x
Motivator

What options do recommend for using rsync to move the splunk database (indexes) to the new server? I have my splunkDB outside of the /opt/splunk directory tree because it is a separate volume (raid array). I've already successfully used tar to get /opt/splunk over there and unpacked it and have it running, but I think that tar is not the tool for moving the index data as it is so large. I'm planning to shut down both splunk instances before moving the splunkdB, is there anything else to do before moving (copying it, actually).

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...