Installation

What are the prerequisites and things to know before moving to Splunk cloud from on-prem environment?

vrmandadi
Builder

Is there a good document or a write up to address the following questions.

1) Dedicated Splunk AWS account to allow multiple datacenters and affiliates to send their data to it
2) Management and deployment of certificates and agent passwords
3) Instance types required for each Splunk component based
4) Other considerations?

Any kind of documents would be helpful

Labels (1)
0 Karma

Vijeta
Influencer

@vrmandadi Are you talking about migrating splunk on-premnise to AWS instances or to Splunk cloud?

0 Karma

woodcock
Esteemed Legend

You need a special forwarder/config to send data in.
You will no longer be able to deploy apps yourself and some apps will be forbidden permanently.
Sending data in is cheap but if you ever decide to migrate significant data out, there is a stiff surcharge.
Splunk will decide when and if you need more resources/CPU/speed/disk whatever.
Splunk will decide if and when you will be upgrading anything.
You will get new features, including doughnut releases first (sometimes good, sometimes very bad).

0 Karma

vrmandadi
Builder

Thank You for your reply @woodcock .So most of the things is done by Professional Splunk team.What are things that I need to take care or decide for this migration to occur and is there any kind of document

Lastly , what do you mean by special forwarder .How is this configured

0 Karma

ChrisG
Splunk Employee
Splunk Employee

See https://docs.splunk.com/Documentation/SplunkCloud/7.2.4/User/ForwardDataToSplunkCloudFromLinux for information about the Splunk Cloud credentials file you need for the universal forwarder.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...