Installation

What is the best way to migrate the Knowledge Objects from an on-prem Splunk Enterprise instance to a Cloud instance?

peeto
New Member

We are in the middle of Cloud migration. We are migrating each index to cloud by re-configuring universal forwarders to send data to Cloud. We haven't moved the Knowledge Objects yet. We would like to know the best efficient way to migrate knowledge objects. Our estimate of the size could be between 2 GB to 5 GB. Our approach is iterative and not big-bang , so would like to provide less disruption to the users while we migrate over the Knowledge Objects. We have a hybrid search head to facilitate the search for indexes in cloud as well as on-prem during the migration.

Labels (1)
0 Karma
1 Solution

pgreer_splunk
Splunk Employee
Splunk Employee

The best method is via Splunk Professional Services. Migrations from on-prem to Cloud is not something that should be done solely by yourself as it is best to have access to the Cloud instance CLI for pieces of the puzzle. Splunk has recently created the ability to have PS perform services in smaller blocks of hours than a single day, so if the migration is small, it is quite affordable to have our PS team perform those tasks required to upload your knowledge objects to your instance.

Some things that will be considered around the migration:
- Apps developed by your enterprise - whether or not they can be loaded into Cloud (requirements around app vetting found here
- security (users/roles) required around your environment (integration with LDAP or SAML for SSO?)
- Any data migration that might be required (historical data if desired, lookups, etc.)

View solution in original post

0 Karma

pgreer_splunk
Splunk Employee
Splunk Employee

The best method is via Splunk Professional Services. Migrations from on-prem to Cloud is not something that should be done solely by yourself as it is best to have access to the Cloud instance CLI for pieces of the puzzle. Splunk has recently created the ability to have PS perform services in smaller blocks of hours than a single day, so if the migration is small, it is quite affordable to have our PS team perform those tasks required to upload your knowledge objects to your instance.

Some things that will be considered around the migration:
- Apps developed by your enterprise - whether or not they can be loaded into Cloud (requirements around app vetting found here
- security (users/roles) required around your environment (integration with LDAP or SAML for SSO?)
- Any data migration that might be required (historical data if desired, lookups, etc.)

0 Karma

peeto
New Member

Thanks. We have reached out to Splunk Cloud Advisory team and working with them.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...