Splunk Enterprise

Configuration Backup

shocko
Contributor

I'm running Splunk Enterprise 8.0.5 on Windows 2016 and looking to upgrade to 8.2.3. We run the following:

  • 2 indexers
  • 1 Search head
  • 1 Master Node [Cluster Master, Deployment Server and License Master]

We currently are only backing up the index files which is very risky so I need to get the configuration backed up as well.  From reading the documents it seems that generally we only need to backup:

  • $SPLUNK_HOME/etc/

Is there any requirement to backup /var/ or any other folders though? 

0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

Basically it should be enough that you are backing up SPLUNK_HOME/etc and SPLUNK_DB directory, even there are some other status files under SPLUNK_HOME/var. If you can do offline update then the easiest/safest way is to do full backup of SPLUNK_HOME and SPLUNK_DB dir for all those nodes. Then the possible rollback to the previous version will be easier.

BUT if you has started those nodes and realise later on that you must do a rollback then you will be lost events which has arrived after update.

r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Basically it should be enough that you are backing up SPLUNK_HOME/etc and SPLUNK_DB directory, even there are some other status files under SPLUNK_HOME/var. If you can do offline update then the easiest/safest way is to do full backup of SPLUNK_HOME and SPLUNK_DB dir for all those nodes. Then the possible rollback to the previous version will be easier.

BUT if you has started those nodes and realise later on that you must do a rollback then you will be lost events which has arrived after update.

r. Ismo

0 Karma

shocko
Contributor

Thanks for the update. What about the KV store? Does that not need to be backed up also ?

0 Karma

isoutamo
SplunkTrust
SplunkTrust
If you are backing up var as offline then you have it. Otherwise you should do it manually.

shocko
Contributor

Thanks. I'm a little confused by the documentation on this regard. I don't see where it specifically references backing up /var/ but i see this which indicates to create a kvstore backup Back up and restore search head cluster settings - Splunk Documentation

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Sorry, I am meaning $SPLUNK_HOME/var not /var.

shocko
Contributor

Ah yes, makes sense now. Offline backup i.e. all services stopped so no need to run the KVStore online backup commands. 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...