Security

Incident Review kv store /lookup migration

arunkuriakose
Explorer

We have two separate splunk instances with ES (standalone not clustered) . Consider it as a HO DR

 

when i try to move to DR instance of splunk and copy /etc/apps , After restarting DR instance all the notables are in new status . Those notables which are closed in HO splunk is also showing as new. What could be the reason?

 

I do know that this is managed as a kv store. If we have to migrate KV store related to this. What are the best practises in this case

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @arunkuriakose ,

I don't know if this could be your use case, but there's a feature to perform backup and restore ok the kv-store.

We used it for DR of DB-Connect.

For more infos see at https://docs.splunk.com/Documentation/Splunk/9.3.0/Admin/BackupKVstore

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...