Splunk Enterprise

Migration of Standalone Splunk Enterprise from server on version 8.2.2.1 to server on version 9.0.8

PComSplunk
Engager

We are currently looking to migrate our Standalone Splunk Enterprise server from the existing ec2 to a new ec2. The new server will be based on AWS Marketplace AMI for version 9.0.8: https://aws.amazon.com/marketplace/pp/prodview-l6oos72bsyaks?sr=0-1&ref_=beagle&applicationId=AWSMPC...

Reason for migration: we want to use the Marketplace AMI while upgrading the Splunk Version

Since this migration involves going from version 8 to version 9, just copying over the apps(they contain the indexes) hasn't given us the result we wanted in our dev/test environment. We end up with no search UI loaded when the search app is copied over from the previous version 8 server to the version 9 server. 

Has anyone else migrated their server this way i.e. jumping versions while migrating to the new server?

What would the community recommend in terms of a scenario that we currently have? Would an in place upgrade to version 9 and then copy over to the new server be a better option/recommended? 

 

 

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

I would recommend an in-place upgrade to version 9 and then copy Splunk to the new server.

In general, one should not copy an entire built-in app (like search) between instances.  Transfer only the local folder.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

3 Ways to Make OpenTelemetry Even Better

My role as an Observability Specialist at Splunk provides me with the opportunity to work with customers of ...

What's New in Splunk Cloud Platform 9.2.2406?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2406 with many ...

Enterprise Security Content Update (ESCU) | New Releases

In August, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...