Hi all,
We're in the process of migrating from pooling to clustering on our search heads. This is still in a testing phase so both are running side-by-side at the moment. The obvious change is that we are no longer using the mounted NFS pool (/splunk_pool) and are instead using local config which is replicated across.
Is there an easy way to migrate all of this data across? For example, we have upwards of 30 dashboards in the pool, yet obviously none of them are in the clustered setup. I can copy these manually across from /splunk_pool/etc/apps/search/local/data/ui/views and put them in /opt/splunk/etc/apps/search/local/data/ui/views/, but I would have to do this manually across all of the clustered nodes. Is there a way that this can be done automagically? I am also worried I will lose individual users saved searches and manual extractions.
Any help would be greatly appreciated!
Best regards,
Alex
You would want to use the deployer to migrate your custom app configurations and private user configurations.
http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Migratefromsearchheadpooling