Splunk Enterprise

Splunk Search Head physical server migration from old server to new physical server

Sathish28
Explorer

 

We have plan to migrate the old physical server to new physical server and the server is a Search Head component in Splunk Environment.
for the new physical server we will be receiving new IP address,

my query is how to configure new IP to the existing Splunk Server Environment

Our Splunk Environment has
1 - Cluster master
4 - indexer
1 - deployment server
1- Search Head
1- monitoring console
1- License Master

DR Servers
1 - Search Head
1- Indexer

0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. I'm not sure what you mean by "DR servers" here since in the main environment you have four indexers and you have only one "DR indexer".

2. Search head must be able to contact CM, indexers and LM (there can be additional requirements if you're using Stream but I'm assuming you aren't). So you should simply install a new SH, replicate (most of) the configuration and state (including kvstore contents) from existing SH and you should be ready to go. Just tell people to use the new address or update the DNS entry to point to the new SH.

Remember about adjusting your network settings (firewall holes) for the new SH and check if you don't have any IP-based or certificate based restrictions on your indexer tier.

0 Karma

Sathish28
Explorer

2. Search head must be able to contact CM, indexers and LM

could you please tell me where to check the search head is connected with CM, indexers and LM in the existing old server 

and when we are migrating to the new server where to make the configurations changes  to contact  CM, indexers and LM

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It's not about Splunk components' config as much as your network config.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...