Installation

How to copy/move KO from one site to another?

woodlandrelic
Path Finder

HI,

So, I have two clustered environments. I want to copy KO from one site to another. They need to have pretty much the same alerts, dashboards, etc. Thanks

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @woodlandrelic,

your Knowledge Objects should be in one or more apps (custom or from Splunkbase), so you should copy these apps from one environment and deploy to the second using the usual ways you have (Deployer, Master Node, Deployment Server).

If they aren't in one or more apps, I hint to rationalize them creating your own apps.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @woodlandrelic,

your Knowledge Objects should be in one or more apps (custom or from Splunkbase), so you should copy these apps from one environment and deploy to the second using the usual ways you have (Deployer, Master Node, Deployment Server).

If they aren't in one or more apps, I hint to rationalize them creating your own apps.

Ciao.

Giuseppe

woodlandrelic
Path Finder

Thank you so much. Unfortunately we are looking for another way to move the KO. Am new to the environment and there is no deployer setup and no access for me yet.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @woodlandrelic,

if in the new enviroament you haven't a Search Head Cluster, you have to follow the same methid and manually copy apps in the new Environment Search Heads.

Ciao.

Giuseppe

woodlandrelic
Path Finder

Hi @gcusello 

How do I do this? Any help would be fantastic. Thank you.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @woodlandrelic,

you have to:

  • make on paper a list of the apps to copy defining the role of the server (Search Head, Indexer or Heavy Forwarder) containing the apps;
  • go in the old environament servers containing the apps and make a copy (tar) of the apps in the list,
  • go in the new environament and copy the apps into $SPLUNK_HOME/etc/apps,
  • restart Splunk in the new environment servers.

remember to put attention to the first step it isn't unuseful!

Ciao.

Giuseppe

woodlandrelic
Path Finder

Hi @gcusello 

Thank you very much.

 

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...