Splunk Enterprise

Lookups migration

nejmeddine
Loves-to-Learn

I installed a new splunk pprod platform and I would like to migrate all the prod data to the new platform.

I restored the searchhead prod cluster on the pprod cluster with the backup and restoration of .bundle as indicated in this link:

https://docs.splunk.com/Documentation/Splunk/8.2.12/DistSearch/BackuprestoreSHC

The problem I have is a difference in the number of lookups between the prod and the pprod (pprod contains 1240 lookups and 58 datamodels while the prod contains 1270 lookups and 59 datamodels). Why do I have this difference even though I restored the pprod cluster with the prod .bundle?
What can I do to have the same number on both platforms?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...