Security

Incident Review kv store /lookup migration

arunkuriakose
Explorer

We have two separate splunk instances with ES (standalone not clustered) . Consider it as a HO DR

 

when i try to move to DR instance of splunk and copy /etc/apps , After restarting DR instance all the notables are in new status . Those notables which are closed in HO splunk is also showing as new. What could be the reason?

 

I do know that this is managed as a kv store. If we have to migrate KV store related to this. What are the best practises in this case

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @arunkuriakose ,

I don't know if this could be your use case, but there's a feature to perform backup and restore ok the kv-store.

We used it for DR of DB-Connect.

For more infos see at https://docs.splunk.com/Documentation/Splunk/9.3.0/Admin/BackupKVstore

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...