Installation

Spleak Search Head Migration from VM to Physical host

anirudhk
Explorer

I have a distributed Splunk setup with a server as (Search Head + Deployment Server + License Server) capabilities and 2 Indexers. We are expanding our enterprise architecture and would like to migrate the Search Head to a Physical as compared to VM that it is installed on currently.

How would I go about migrating the search head to physical by leaving the license server and Deployment server functionality.

Thanks
Anirudh

Tags (2)
0 Karma
1 Solution

kaufmanm
Communicator

You can install Splunk on the new server and then set up the distributed search settings through the UI under Settings -> Distributed Search, adding all the search peers that the VM currently connects to. You'll also likely want to copy over some custom apps or user settings that reside in /opt/splunk/etc/apps and /opt/splunk/etc/users respectively. You can leave the VM as is, or once you have the new search head set up, you could remove the search peers through the UI, or by removing them from /opt/splunk/etc/system/local/distsearch.conf. There's no cost to having two servers configured for distributed search, so I don't see a good reason to turn that off.

View solution in original post

0 Karma

kaufmanm
Communicator

You can install Splunk on the new server and then set up the distributed search settings through the UI under Settings -> Distributed Search, adding all the search peers that the VM currently connects to. You'll also likely want to copy over some custom apps or user settings that reside in /opt/splunk/etc/apps and /opt/splunk/etc/users respectively. You can leave the VM as is, or once you have the new search head set up, you could remove the search peers through the UI, or by removing them from /opt/splunk/etc/system/local/distsearch.conf. There's no cost to having two servers configured for distributed search, so I don't see a good reason to turn that off.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...