Splunk IT Service Intelligence

Is there a formal process for copying Splunk IT Service Intelligence to another server?

Jarohnimo
Builder

I have set up Splunk IT Service Intelligence on my standalone Splunk server, but now have a need to expand. I have recently added a search head to this indexer, so now the responsibilities are split up a little. I copied the apps directory along with my user's directory to the new box. Everything works fine, ITSI copied over, but none of the services and or KPI's are there. I imagine they must not be saved or exist within the apps directory. Is there another set of folders I should be copying?

Is there a formal process for copying ITSI over to another server?

Splunk please see to it this Message makes it to the Splunk Developers
This is a formal request for Splunk to look into a Master Configuration for splunk much like the configuration Database in Microsoft Sharepoint where when you add a brand new node to an existing implementation you don't have to manually make edits or copy files over to the new server in order for it to be up to speed with the existing configurations like other nodes within that farm.

Ideally if we stand up a new node, whichever server you've designated as your Master, or Master Config, that's where all other servers where go to in order to retrieve their reports, dashboards, lookups, KVstore, csv''s apps, etc, etc, etc... This way we don't have to individually manage content across multiple web servers or go out and buy a 3rd party tool to manage synchronizing content.

The benefit of having a master configuration that all other nodes copy from is it will be easy to scale out and move services around. LET THE CLONING BEGIN SPLUNK 6.5 we want this!

0 Karma
1 Solution

Jarohnimo
Builder

Found the answer,

Best way is to package up the Kv Store and restore on new ITSI heads:

http://docs.splunk.com/Documentation/ITSI/2.1.0/Configure/BackupandRestoreITSIconfig

View solution in original post

Jarohnimo
Builder

Found the answer,

Best way is to package up the Kv Store and restore on new ITSI heads:

http://docs.splunk.com/Documentation/ITSI/2.1.0/Configure/BackupandRestoreITSIconfig

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...