Splunk Search

Migration Issue

Amandeepsin
New Member

We are about to migrate stuff from one cloud env to AWS.. set up is done.. issue is :

  • we have old splunk instance where indexer and search head was on same server.
  • Now, we have segregated the search head and indexer.
  • I want to migrate all the dashboards, alerts, reports to new instance..
  • main issue is :
  • I cannot copy as it is by following migration as stated in splunk because previously we have splunk search head and indexer on same server. Now, we have two instances simply copy and paste will not work
  • Secondly, on old splunk instance we have user on splunk, now we have configured SAML. I don't know If simply copy and paste of the user will work

Kindly sugest

Tags (1)
0 Karma

dkeck
Influencer

Please accept the answer if it helped. Thank you 🙂

0 Karma

lakshman239
Influencer

If the dashboards (views), alerts and reports were in any specific app, you can take the files or the app [ e.g. savedsearches.conf, props.conf] and move them to new instance and it should work.

You just need to ensure the required indexers and other indexer specific settings/requirements are added in the indexer.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...