Splunk Enterprise Security

How to migrate Splunk Enterprise Security from VM to new physical host?

discenzadoe
Explorer

I need to migrate my current ES installation from a VM to a physical host, due to performance issues in the virtual instance. 

Because of internal policies, I cannot simply clone the system via rsync, as the new physical box must have a new name to indicate it isn't a VM.

I tried copying the /opt/splunk/etc/system subdirectory of the new server to a backup location, then using rsync to replicate the /opt/splunk/etc subdirectory structure from the functional VM to the new server. I copied the backup of system back into place, except for the server.conf which I merged the two together.

Tons of errors. Tons of missing data in the ES dashboards.

What am I missing?

Thanks in advance for any suggestions.

Labels (2)
0 Karma

lakshman239
Influencer

Have you considered fresh ES install on the new physical server and migrate the data from your VM?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...