- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HI,
So, I have two clustered environments. I want to copy KO from one site to another. They need to have pretty much the same alerts, dashboards, etc. Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @woodlandrelic,
your Knowledge Objects should be in one or more apps (custom or from Splunkbase), so you should copy these apps from one environment and deploy to the second using the usual ways you have (Deployer, Master Node, Deployment Server).
If they aren't in one or more apps, I hint to rationalize them creating your own apps.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @woodlandrelic,
your Knowledge Objects should be in one or more apps (custom or from Splunkbase), so you should copy these apps from one environment and deploy to the second using the usual ways you have (Deployer, Master Node, Deployment Server).
If they aren't in one or more apps, I hint to rationalize them creating your own apps.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you so much. Unfortunately we are looking for another way to move the KO. Am new to the environment and there is no deployer setup and no access for me yet.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @woodlandrelic,
if in the new enviroament you haven't a Search Head Cluster, you have to follow the same methid and manually copy apps in the new Environment Search Heads.
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @gcusello
How do I do this? Any help would be fantastic. Thank you.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi @woodlandrelic,
you have to:
- make on paper a list of the apps to copy defining the role of the server (Search Head, Indexer or Heavy Forwarder) containing the apps;
- go in the old environament servers containing the apps and make a copy (tar) of the apps in the list,
- go in the new environament and copy the apps into $SPLUNK_HOME/etc/apps,
- restart Splunk in the new environment servers.
remember to put attention to the first step it isn't unuseful!
Ciao.
Giuseppe
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
