Splunk Enterprise Security

What is considered a full back up of Search Head?

pfabrizi
Path Finder

I am reading the upgrade instructions for ES 5.0. It indicates to take a full backup of the search head. Is that just copying /opt/splunk to a backup location?

Thanks!

1 Solution

skoelpin
SplunkTrust
SplunkTrust

Yes. The data lives on the indexers (with the exception of a summary index) and all your knowledge objects live on the search head. So you can simply take a backup of /opt/splunk and you will have a complete backup of all your knowledge objects which consist of saved searches, dashboards, extractions, lookups, etc..

https://docs.splunk.com/Documentation/VMW/3.4.1/User/KnowledgeObjects

View solution in original post

skoelpin
SplunkTrust
SplunkTrust

Yes. The data lives on the indexers (with the exception of a summary index) and all your knowledge objects live on the search head. So you can simply take a backup of /opt/splunk and you will have a complete backup of all your knowledge objects which consist of saved searches, dashboards, extractions, lookups, etc..

https://docs.splunk.com/Documentation/VMW/3.4.1/User/KnowledgeObjects

pfabrizi
Path Finder

Thank You!

0 Karma

adonio
Ultra Champion

that will do

0 Karma
Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...