Getting Data In

What are the steps for a Splunk SH Migration from Cent OS to REDHAT from one VM to another VM?

kiranhar
Explorer

Team,

I need your assistance with the below task.

I need to migrate Splunk sh-2 (Non ES instance) from Cent OS to REDHAT from one VM to another VM.

I would appreciate it if you can provide step by step guide for this migration.

Note: We need to maintain the same IP address / Host Name of the existing VM ( Splunk Server).

Labels (1)
0 Karma
1 Solution

gcusello
Esteemed Legend

Hi @kiranhar,

ok, so the path is the one I described in my previous post.

tell me if I can help you more, otherwise, please accept one answer for the other people of Community.

Ciao.

Giuseppe

P.S.: Karma Points are appreciated 😉

View solution in original post

0 Karma

gcusello
Esteemed Legend

Hi @kiranhar,

folow these steps:

  • stop Splunk on the old SH,
  • tar all the /opt/splunk folder
  • copy the tar file in another system,
  • stop the old VM,
  • run the new VM,
  • copy the tar file on the new VM,
  • create the splunk user splunk group,
  • untar the tar file,
  • run Splunk,
  • run the command to automaticall start Splunk at boot (/opt/splunk/bin/splunk enable boot-start).

It's different is you have a different IP or hostname.

Ciao.

Giuseppe

0 Karma

kiranhar
Explorer

Hi Thanks for your response.

We wanted to keep the old setup until we migrate Splunk to the new VM. So, we have a new VM with new IP and new Hostname, later will change the IP and Host Name on the new Server as old one. Please advise on the steps for this scenario.

 

Awaiting your response.

0 Karma

gcusello
Esteemed Legend

Hi @kiranhar,

if you want to migrate to another VM with different hostname and IP, you have to follow the same procedure, but, before restart the new VM, you have to manually modify the following conf files:

  • $SPLUNK_HOME/etc/system/local/server.conf
  • $SPLUNK_HOME/etc/system/local/inputs.conf

replacing the old hostname with the new one.

Ciao.

Giuseppe

0 Karma

kiranhar
Explorer

Hi,

Thanks for your respons. No, it is the same IP and Host to maintain on the new VM.

0 Karma

gcusello
Esteemed Legend

Hi @kiranhar,

ok, so the path is the one I described in my previous post.

tell me if I can help you more, otherwise, please accept one answer for the other people of Community.

Ciao.

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

kiranhar
Explorer

Thanks. Also, please advise, on how to create a Splunk user and Splunk group on the new Linux Server (Redhat). Please provide the steps.

0 Karma

gcusello
Esteemed Legend

Hi @kiranhar,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma

gcusello
Esteemed Legend

Hi @kiranhar,

I'm sorry but I'm a little rusty on Linux, anyway, you can find this on Google:

https://linuxize.com/post/how-to-add-user-to-group-in-linux/

or something else.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through: An introduction to the Splunk Threat ...