Splunk Search

Migration Issue

Amandeepsin
New Member

We are about to migrate stuff from one cloud env to AWS.. set up is done.. issue is :

  • we have old splunk instance where indexer and search head was on same server.
  • Now, we have segregated the search head and indexer.
  • I want to migrate all the dashboards, alerts, reports to new instance..
  • main issue is :
  • I cannot copy as it is by following migration as stated in splunk because previously we have splunk search head and indexer on same server. Now, we have two instances simply copy and paste will not work
  • Secondly, on old splunk instance we have user on splunk, now we have configured SAML. I don't know If simply copy and paste of the user will work

Kindly sugest

Tags (1)
0 Karma

dkeck
Influencer

Please accept the answer if it helped. Thank you 🙂

0 Karma

lakshman239
SplunkTrust
SplunkTrust

If the dashboards (views), alerts and reports were in any specific app, you can take the files or the app [ e.g. savedsearches.conf, props.conf] and move them to new instance and it should work.

You just need to ensure the required indexers and other indexer specific settings/requirements are added in the indexer.

0 Karma
Get Updates on the Splunk Community!

Last Chance to Submit Your Paper For BSides Splunk - Deadline is August 12th!

Hello everyone! Don't wait to submit - The deadline is August 12th! We have truly missed the community so ...

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...

DevSecOps: Why You Should Care and How To Get Started

 WATCH NOW In this Tech Talk we will talk about what people mean by DevSecOps and deep dive into the different ...