Installation

How to copy/move KO from one site to another?

woodlandrelic
Path Finder

HI,

So, I have two clustered environments. I want to copy KO from one site to another. They need to have pretty much the same alerts, dashboards, etc. Thanks

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @woodlandrelic,

your Knowledge Objects should be in one or more apps (custom or from Splunkbase), so you should copy these apps from one environment and deploy to the second using the usual ways you have (Deployer, Master Node, Deployment Server).

If they aren't in one or more apps, I hint to rationalize them creating your own apps.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @woodlandrelic,

your Knowledge Objects should be in one or more apps (custom or from Splunkbase), so you should copy these apps from one environment and deploy to the second using the usual ways you have (Deployer, Master Node, Deployment Server).

If they aren't in one or more apps, I hint to rationalize them creating your own apps.

Ciao.

Giuseppe

woodlandrelic
Path Finder

Thank you so much. Unfortunately we are looking for another way to move the KO. Am new to the environment and there is no deployer setup and no access for me yet.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @woodlandrelic,

if in the new enviroament you haven't a Search Head Cluster, you have to follow the same methid and manually copy apps in the new Environment Search Heads.

Ciao.

Giuseppe

woodlandrelic
Path Finder

Hi @gcusello 

How do I do this? Any help would be fantastic. Thank you.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @woodlandrelic,

you have to:

  • make on paper a list of the apps to copy defining the role of the server (Search Head, Indexer or Heavy Forwarder) containing the apps;
  • go in the old environament servers containing the apps and make a copy (tar) of the apps in the list,
  • go in the new environament and copy the apps into $SPLUNK_HOME/etc/apps,
  • restart Splunk in the new environment servers.

remember to put attention to the first step it isn't unuseful!

Ciao.

Giuseppe

woodlandrelic
Path Finder

Hi @gcusello 

Thank you very much.

 

0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...