Installation

Migrating Splunk instance from Windows to Linux: steps to migrate apps, saved searches, permissions, and reinstall apps?

gaddams
Explorer

Hello,

We are migrating our Splunk instance from Windows to Linux. As part of the migration, we were successfully able to migrate the index data.

We would like to know the procedure to migrate apps, saved searches, permissions. Is there any migration procedure for them or do we need to reinstall the apps?

Thanks

Labels (3)
Tags (2)
0 Karma

MuS
SplunkTrust
SplunkTrust

Hi gaddams,

if you follow the docs http://docs.splunk.com/Documentation/Splunk/6.1.4/Installation/MigrateaSplunkinstance#What_to_consid...
in step 2:

2. Copy the entire contents of the $SPLUNK_HOME directory from the old server to the new server.

This is where all apps, saved searches and so on will be copied to the new server.
In your case, since you already copied the indexes, exclude the $SPLUNK_DB from this copy process.

hope this helps ...

cheers, MuS

0 Karma

gaddams
Explorer

I did this but because the web server is configured to use SSL and since there is change in the binaries, I had to replace the windows binaries with linux binaries by replacing bin and lib folders and also system folder to exclude certificates.

I observed that some of the apps were not working automatically and had to be reinstalled.

Thanks

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...