Is there a concise guide for migrating an ITSI search head to a search head cluster?

Path Finder

I looked at the install guide for ITSI into a SHC as well as a doc for migrating from a single search head to a SHC. However, trying to parse together the steps and being successful has been problematic.

I've searched a ton and been unable to find a doc that addresses this specific use case. It doesn't seem like it would be a unique scenario. Can anyone point me to a guide for accomplishing this migration?

Thank you,


Labels (1)
Tags (3)

Splunk Employee
Splunk Employee

I reached out to one of the SME's for this product and they stated that there isn't a document which covers the process. It is typically handled by Professional Services due to the complexity which includes migrating the KVStore.

Sr. Technical Support Engineer
0 Karma

Path Finder

csprice, we are actively looking to migrate this scenario as well and running into similar challenges. We've engaged Splunk support/PS to help; I'll be happy to let you know what we find out! If you learn anything new in the meantime, can you please let me know?

Thank you!

0 Karma

Path Finder

Alright, I've had some limited success with regard to this issue.

The steps I've completed are as follows:
- build the SHC (this is the easy part)
- ensured /local configurations were maintained across original and new (authentication, authorization, etc)
- used the process detailed here: This got some of the config across, but my KPI's weren't appearing
- finally used: (this, as noted by the name, allows you to backup the kvstore and move it to the new cluster)

I'm still fighting a couple things (glass tables are not showing up on the new cluster) but I'm close. Hopefully this gives someone a point in the right direction.

0 Karma
Get Updates on the Splunk Community!

Platform Highlights | November 2022 Newsletter

 November 2022 Skill Up on Splunk with our New Builder Tech Talk SeriesCan you build it? Yes you can! *play ...

Splunk Education - Fast Start Program!

Welcome to Splunk Education! Splunk training programs are designed to enable you to get started quickly and ...

Five Subtly Different Ways of Adding Manual Instrumentation in Java

You can find the code of this example on GitHub here. Please feel free to star the repository to keep in ...