Splunk Enterprise

Decommissioning server SPLUNK was running on & SPLUNK retiring

Orange_girl
Loves-to-Learn Everything

Hello, 

we have decided to retire SPLUNK and the server that SPLUNK was running on. If the server is decommissioned, do we still need to decommission SPLUNK - or would one equal the other? If it wouldn't, is there a way to still decommission SPLUNK after the server has been decommissioned?

Thank you. 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

From Splunk's perspective, no action is needed to stop using the software.  Your company, however, may have its own requirements, such as archiving the data before decommissioning the server.

---
If this reply helps you, Karma would be appreciated.
0 Karma

Orange_girl
Loves-to-Learn Everything

thank you for your response! Yes, what I am referring to is just no longer using SPLUNK at all, not just one indexer. The question was more in terms of any scripts or data that was not removed from SPLUNK specifically before decommissioning the server. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

It depends on what is meant by "decommissioning Splunk".  There is a process for removing a member from a search head or indexer cluster.  Decommissioning an independent indexer typically would mean moving that indexer's data to another indexer.

If you will not be running Splunk anywhere then just stop Splunk and retire the server.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...