Installation

Is there a concise guide for migrating an ITSI search head to a search head cluster?

csprice
Path Finder

I looked at the install guide for ITSI into a SHC as well as a doc for migrating from a single search head to a SHC. However, trying to parse together the steps and being successful has been problematic.

I've searched a ton and been unable to find a doc that addresses this specific use case. It doesn't seem like it would be a unique scenario. Can anyone point me to a guide for accomplishing this migration?

Thank you,

Steve

Labels (1)
Tags (3)

jcrabb_splunk
Splunk Employee
Splunk Employee

I reached out to one of the SME's for this product and they stated that there isn't a document which covers the process. It is typically handled by Professional Services due to the complexity which includes migrating the KVStore.

Jacob
Sr. Technical Support Engineer
0 Karma

paulstout
Path Finder

csprice, we are actively looking to migrate this scenario as well and running into similar challenges. We've engaged Splunk support/PS to help; I'll be happy to let you know what we find out! If you learn anything new in the meantime, can you please let me know?

Thank you!

0 Karma

csprice
Path Finder

Alright, I've had some limited success with regard to this issue.

The steps I've completed are as follows:
- build the SHC (this is the easy part)
- ensured /local configurations were maintained across original and new (authentication, authorization, etc)
- used the process detailed here: http://docs.splunk.com/Documentation/Splunk/6.5.2/DistSearch/Migratefromstandalonesearchheads This got some of the config across, but my KPI's weren't appearing
- finally used: https://docs.splunk.com/Documentation/ITSI/2.6.0/Configure/kvstore_to_json.pyoperations (this, as noted by the name, allows you to backup the kvstore and move it to the new cluster)

I'm still fighting a couple things (glass tables are not showing up on the new cluster) but I'm close. Hopefully this gives someone a point in the right direction.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...