Knowledge Management

Splunk: How to backup/restore Splunk's data?

htkwan
Path Finder

Hello,
Pls advise how one can backup from an existing splunk (7.0) and restore the saved splunk's data to another new splunk (latest version). I can schedule a shutdown for the backup/restore. Thanks

Tags (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @htkwan,
if you want to upgrade an existing installation, you could backup your data and installation for sure and then upgrade your Splunk installation to the new version.
If instead you want to copy installation to a new instance, make restore of the backupped instace (changing hostnames) and then upgrade to the latest version.
In other words, the best approach is to make backup and restore of the old versione and to leave Splunk automatic procedure to upgrade installation.
You could also copy some file of $SPLUNK_HOME/etc from the old to the new installation, but I don't like it!

Ciao.
Giuseppe

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Introducing the 2026 - 2027 SplunkTrust cohort!

The goal of the SplunkTrust™ membership has historically been to acknowledge and recognize those who go above ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...