Knowledge Management

Splunk: How to backup/restore Splunk's data?

htkwan
Path Finder

Hello,
Pls advise how one can backup from an existing splunk (7.0) and restore the saved splunk's data to another new splunk (latest version). I can schedule a shutdown for the backup/restore. Thanks

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @htkwan,
if you want to upgrade an existing installation, you could backup your data and installation for sure and then upgrade your Splunk installation to the new version.
If instead you want to copy installation to a new instance, make restore of the backupped instace (changing hostnames) and then upgrade to the latest version.
In other words, the best approach is to make backup and restore of the old versione and to leave Splunk automatic procedure to upgrade installation.
You could also copy some file of $SPLUNK_HOME/etc from the old to the new installation, but I don't like it!

Ciao.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...

Level Up Your Workflow: Mastering Splunk Cloud Management via Terraform

Tech Talk Recap   From Chaos to Control: Scaling Splunk Cloud with Infrastructure as Code Managing apps in ...