Installation

How to copy/move KO from one site to another?

woodlandrelic
Path Finder

HI,

So, I have two clustered environments. I want to copy KO from one site to another. They need to have pretty much the same alerts, dashboards, etc. Thanks

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @woodlandrelic,

your Knowledge Objects should be in one or more apps (custom or from Splunkbase), so you should copy these apps from one environment and deploy to the second using the usual ways you have (Deployer, Master Node, Deployment Server).

If they aren't in one or more apps, I hint to rationalize them creating your own apps.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @woodlandrelic,

your Knowledge Objects should be in one or more apps (custom or from Splunkbase), so you should copy these apps from one environment and deploy to the second using the usual ways you have (Deployer, Master Node, Deployment Server).

If they aren't in one or more apps, I hint to rationalize them creating your own apps.

Ciao.

Giuseppe

woodlandrelic
Path Finder

Thank you so much. Unfortunately we are looking for another way to move the KO. Am new to the environment and there is no deployer setup and no access for me yet.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @woodlandrelic,

if in the new enviroament you haven't a Search Head Cluster, you have to follow the same methid and manually copy apps in the new Environment Search Heads.

Ciao.

Giuseppe

woodlandrelic
Path Finder

Hi @gcusello 

How do I do this? Any help would be fantastic. Thank you.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @woodlandrelic,

you have to:

  • make on paper a list of the apps to copy defining the role of the server (Search Head, Indexer or Heavy Forwarder) containing the apps;
  • go in the old environament servers containing the apps and make a copy (tar) of the apps in the list,
  • go in the new environament and copy the apps into $SPLUNK_HOME/etc/apps,
  • restart Splunk in the new environment servers.

remember to put attention to the first step it isn't unuseful!

Ciao.

Giuseppe

woodlandrelic
Path Finder

Hi @gcusello 

Thank you very much.

 

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...