Installation

Moving from Search Head pooling to Search Head clustering -- replicating dashboards, saved searches, etc.?

alekksi
Communicator

Hi all,

We're in the process of migrating from pooling to clustering on our search heads. This is still in a testing phase so both are running side-by-side at the moment. The obvious change is that we are no longer using the mounted NFS pool (/splunk_pool) and are instead using local config which is replicated across.
Is there an easy way to migrate all of this data across? For example, we have upwards of 30 dashboards in the pool, yet obviously none of them are in the clustered setup. I can copy these manually across from /splunk_pool/etc/apps/search/local/data/ui/views and put them in /opt/splunk/etc/apps/search/local/data/ui/views/, but I would have to do this manually across all of the clustered nodes. Is there a way that this can be done automagically? I am also worried I will lose individual users saved searches and manual extractions.

Any help would be greatly appreciated!

Best regards,
Alex

Labels (1)
0 Karma

rphillips_splk
Splunk Employee
Splunk Employee

You would want to use the deployer to migrate your custom app configurations and private user configurations.

http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Migratefromsearchheadpooling

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...