Splunk Search

Exporting Splunk configurations

alexsuv
Engager

I would like to export the Splunk for CEF configuration from one Splunk server, in order to import it to another Splunk.

I assume there is no way to export the config from the UI (please correct if it is wrong).

So I exported the all the files from the CLI /opt/splunk/etc/apps/splunk_app_cef/local:

zip -r config-app-for-cef.zip /opt/splunk/etc/apps/splunk_app_cef/local/*

Then, to import it, I paste all these files into the same dir.

Is this a correct and recommended method of exporting/importing?

Thank you.

Tags (1)
0 Karma
1 Solution

masonmorales
Influencer

I would suggest zip -r config-app-for-cef.zip /opt/splunk/etc/apps/splunk_app_cef/

If the app ships with default configurations, you won't have those if you only export the local folder. Zipping the entire $SPLUNK_HOME/etc/apps/MYAPP is the easiest manual way to copy app configurations over to another Splunk server.

Just make sure you restart Splunk on the target server in order for it to pickup the new app.

View solution in original post

0 Karma

masonmorales
Influencer

I would suggest zip -r config-app-for-cef.zip /opt/splunk/etc/apps/splunk_app_cef/

If the app ships with default configurations, you won't have those if you only export the local folder. Zipping the entire $SPLUNK_HOME/etc/apps/MYAPP is the easiest manual way to copy app configurations over to another Splunk server.

Just make sure you restart Splunk on the target server in order for it to pickup the new app.

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi alexsuv,

this is a good approach as long as you have CLI access to the server.
If not, you can try this app https://splunkbase.splunk.com/app/2613/ made by @martin_mueller it works just fine and your app is packaged and ready as a spl file.

Hope this helps ...

cheers, MuS

martin_mueller
SplunkTrust
SplunkTrust

Grabbing the App Exporter linked above will let you do things through the UI entirely, assuming you can access your management port.

Do note, all approaches only copy settings shared within the app or globally, private settings won't be copied.

0 Karma

alexsuv
Engager

Thank you 🙂

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Detection Engineering Office Hours: Real-World Troubleshooting & Q&A

[REGISTER HERE] This thread is for the Community Office Hours session on Detection Engineering Office Hours: ...

Developer Spotlight with Mika Borner

From Hackathon Winner to Enterprise Leader    Mika Borner, CEO and Founder of Datapunctum AG, has been ...

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...