Knowledge Management

Splunk: How to backup/restore Splunk's data?

htkwan
Path Finder

Hello,
Pls advise how one can backup from an existing splunk (7.0) and restore the saved splunk's data to another new splunk (latest version). I can schedule a shutdown for the backup/restore. Thanks

Tags (1)
0 Karma

gcusello
Legend

Hi @htkwan,
if you want to upgrade an existing installation, you could backup your data and installation for sure and then upgrade your Splunk installation to the new version.
If instead you want to copy installation to a new instance, make restore of the backupped instace (changing hostnames) and then upgrade to the latest version.
In other words, the best approach is to make backup and restore of the old versione and to leave Splunk automatic procedure to upgrade installation.
You could also copy some file of $SPLUNK_HOME/etc from the old to the new installation, but I don't like it!

Ciao.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Forwarders and Forced Time Based Load Balancing

Splunk customers use universal forwarders to collect and send data to Splunk. A universal forwarder can send ...

NEW! Log Views in Splunk Observability Dashboards Gives Context From a Single Page

Today, Splunk Observability releases log views, a new feature for users to add their logs data from Splunk Log ...

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...