Splunk Enterprise Security

What is considered a full back up of Search Head?

pfabrizi
Path Finder

I am reading the upgrade instructions for ES 5.0. It indicates to take a full backup of the search head. Is that just copying /opt/splunk to a backup location?

Thanks!

1 Solution

skoelpin
SplunkTrust
SplunkTrust

Yes. The data lives on the indexers (with the exception of a summary index) and all your knowledge objects live on the search head. So you can simply take a backup of /opt/splunk and you will have a complete backup of all your knowledge objects which consist of saved searches, dashboards, extractions, lookups, etc..

https://docs.splunk.com/Documentation/VMW/3.4.1/User/KnowledgeObjects

View solution in original post

skoelpin
SplunkTrust
SplunkTrust

Yes. The data lives on the indexers (with the exception of a summary index) and all your knowledge objects live on the search head. So you can simply take a backup of /opt/splunk and you will have a complete backup of all your knowledge objects which consist of saved searches, dashboards, extractions, lookups, etc..

https://docs.splunk.com/Documentation/VMW/3.4.1/User/KnowledgeObjects

pfabrizi
Path Finder

Thank You!

0 Karma

adonio
Ultra Champion

that will do

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...