Installation

Moving from Search Head pooling to Search Head clustering -- replicating dashboards, saved searches, etc.?

alekksi
Communicator

Hi all,

We're in the process of migrating from pooling to clustering on our search heads. This is still in a testing phase so both are running side-by-side at the moment. The obvious change is that we are no longer using the mounted NFS pool (/splunk_pool) and are instead using local config which is replicated across.
Is there an easy way to migrate all of this data across? For example, we have upwards of 30 dashboards in the pool, yet obviously none of them are in the clustered setup. I can copy these manually across from /splunk_pool/etc/apps/search/local/data/ui/views and put them in /opt/splunk/etc/apps/search/local/data/ui/views/, but I would have to do this manually across all of the clustered nodes. Is there a way that this can be done automagically? I am also worried I will lose individual users saved searches and manual extractions.

Any help would be greatly appreciated!

Best regards,
Alex

Labels (1)
0 Karma

rphillips_splk
Splunk Employee
Splunk Employee

You would want to use the deployer to migrate your custom app configurations and private user configurations.

http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Migratefromsearchheadpooling

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...