Splunk Enterprise

Splunk Search Head physical server migration from old server to new physical server

Sathish28
Explorer

 

We have plan to migrate the old physical server to new physical server and the server is a Search Head component in Splunk Environment.
for the new physical server we will be receiving new IP address,

my query is how to configure new IP to the existing Splunk Server Environment

Our Splunk Environment has
1 - Cluster master
4 - indexer
1 - deployment server
1- Search Head
1- monitoring console
1- License Master

DR Servers
1 - Search Head
1- Indexer

0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. I'm not sure what you mean by "DR servers" here since in the main environment you have four indexers and you have only one "DR indexer".

2. Search head must be able to contact CM, indexers and LM (there can be additional requirements if you're using Stream but I'm assuming you aren't). So you should simply install a new SH, replicate (most of) the configuration and state (including kvstore contents) from existing SH and you should be ready to go. Just tell people to use the new address or update the DNS entry to point to the new SH.

Remember about adjusting your network settings (firewall holes) for the new SH and check if you don't have any IP-based or certificate based restrictions on your indexer tier.

0 Karma

Sathish28
Explorer

2. Search head must be able to contact CM, indexers and LM

could you please tell me where to check the search head is connected with CM, indexers and LM in the existing old server 

and when we are migrating to the new server where to make the configurations changes  to contact  CM, indexers and LM

0 Karma

PickleRick
SplunkTrust
SplunkTrust

It's not about Splunk components' config as much as your network config.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...