Splunk Enterprise

Splunk Migration of Search Head and Deployment Server from old Linux Distro to new Linux Distro

n3wbi3
Loves-to-Learn Lots

I want to migrate my clustered environment from one Linux to another.

Is it possible to migrate search head and deployment server first and then the indexers on the other day?

CentOS and the new distro is RHEL? Any Ideas or suggestions?

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

There are many threads about migrating environments in different scenarios. Use the search 🙂

General idea is that your environment should be consistent in terms of used OS and its version but there is no explicit requirement that SH tier must be on the same OS distribution as the indexer-tier (although it is of course best to have a relatively homogenous environment for maintenance reasons) or that the DS must be on the same OS as SHs.

 

0 Karma

fredclown
Builder

This is the beauty of using DNS CNames to reference all your Splunk servers in configuration. Ideally you don't put references to any physical names in your configs. That way when you switch servers you can build your new server along side your old server and then when you want to switch to a new servers you just flip the CName over to the new server.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...