We are in the middle of Cloud migration. We are migrating each index to cloud by re-configuring universal forwarders to send data to Cloud. We haven't moved the Knowledge Objects yet. We would like to know the best efficient way to migrate knowledge objects. Our estimate of the size could be between 2 GB to 5 GB. Our approach is iterative and not big-bang , so would like to provide less disruption to the users while we migrate over the Knowledge Objects. We have a hybrid search head to facilitate the search for indexes in cloud as well as on-prem during the migration.
The best method is via Splunk Professional Services. Migrations from on-prem to Cloud is not something that should be done solely by yourself as it is best to have access to the Cloud instance CLI for pieces of the puzzle. Splunk has recently created the ability to have PS perform services in smaller blocks of hours than a single day, so if the migration is small, it is quite affordable to have our PS team perform those tasks required to upload your knowledge objects to your instance.
Some things that will be considered around the migration:
- Apps developed by your enterprise - whether or not they can be loaded into Cloud (requirements around app vetting found here
- security (users/roles) required around your environment (integration with LDAP or SAML for SSO?)
- Any data migration that might be required (historical data if desired, lookups, etc.)
The best method is via Splunk Professional Services. Migrations from on-prem to Cloud is not something that should be done solely by yourself as it is best to have access to the Cloud instance CLI for pieces of the puzzle. Splunk has recently created the ability to have PS perform services in smaller blocks of hours than a single day, so if the migration is small, it is quite affordable to have our PS team perform those tasks required to upload your knowledge objects to your instance.
Some things that will be considered around the migration:
- Apps developed by your enterprise - whether or not they can be loaded into Cloud (requirements around app vetting found here
- security (users/roles) required around your environment (integration with LDAP or SAML for SSO?)
- Any data migration that might be required (historical data if desired, lookups, etc.)
Thanks. We have reached out to Splunk Cloud Advisory team and working with them.