Installation

Moving from Search Head pooling to Search Head clustering -- replicating dashboards, saved searches, etc.?

alekksi
Communicator

Hi all,

We're in the process of migrating from pooling to clustering on our search heads. This is still in a testing phase so both are running side-by-side at the moment. The obvious change is that we are no longer using the mounted NFS pool (/splunk_pool) and are instead using local config which is replicated across.
Is there an easy way to migrate all of this data across? For example, we have upwards of 30 dashboards in the pool, yet obviously none of them are in the clustered setup. I can copy these manually across from /splunk_pool/etc/apps/search/local/data/ui/views and put them in /opt/splunk/etc/apps/search/local/data/ui/views/, but I would have to do this manually across all of the clustered nodes. Is there a way that this can be done automagically? I am also worried I will lose individual users saved searches and manual extractions.

Any help would be greatly appreciated!

Best regards,
Alex

Labels (1)
0 Karma

rphillips_splk
Splunk Employee
Splunk Employee

You would want to use the deployer to migrate your custom app configurations and private user configurations.

http://docs.splunk.com/Documentation/Splunk/latest/DistSearch/Migratefromsearchheadpooling

0 Karma
Get Updates on the Splunk Community!

Get Inspired! We’ve Got Validation that Your Hard Work is Paying Off

We love our Splunk Community and want you to feel inspired by all your hard work! Eric Fusilero, our VP of ...

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...