- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Support team and Diag File - Migrate / reproduce a Splunk instance

Hi All.. we were wondering why Splunk Support team would require the "diag file" when we open a support ticket?
is that - the splunk support team can "reproduce" my splunk instance on their lab setup to do the analysis?
is it possible? - i mean, from a diag file, can we "Reproduce" the splunk instance?
(untar the diag file, copy the "etc" directory to a newly installed splunk instance and start the splunk.. will it be a reproduction of the old setup?)
thanks,..
Sekar
PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Diag files do not fully reproduce a Splunk instance. Your data, for example, is not in the diag file. It mainly contains your config files so Splunk support can better diagnose your problem. To see what is included in the file, run splunk diag
on the command line then use tar -zlf <diag file>
.
If this reply helps you, Karma would be appreciated.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Adding to rich's answer, splunk support uses undiag tools and load your data. Predefined dashboards and analysis methods gives them an overview about how your system was performing. So they use it for reproducing your problem rather than recreating the environment.
Please refer to Diag contents for more information about diag contents and the video gives an introduction on how its being used.
What goes around comes around. If it helps, hit it with Karma 🙂
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Thanks Rich..
Thanks Renjith..Your answer answered half of my question.
Yeah, i am not looking to recreate / migrate splunk instance with its diag alone. As you said, we also would like to reproduce the problem(not recreate the whole environment).
Is it possible for us(for splunk customers) or, only splunk support can do that?
Sekar
PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


The diag by itself is useful, but is not always enough. It only contains configs for a single system so any cluster-related problem may require other information to reproduce. Similarly, a problem caused by data may not be reproducible using only the diag.
If this reply helps you, Karma would be appreciated.
