Splunk Search

Migration Issue

Amandeepsin
New Member

We are about to migrate stuff from one cloud env to AWS.. set up is done.. issue is :

  • we have old splunk instance where indexer and search head was on same server.
  • Now, we have segregated the search head and indexer.
  • I want to migrate all the dashboards, alerts, reports to new instance..
  • main issue is :
  • I cannot copy as it is by following migration as stated in splunk because previously we have splunk search head and indexer on same server. Now, we have two instances simply copy and paste will not work
  • Secondly, on old splunk instance we have user on splunk, now we have configured SAML. I don't know If simply copy and paste of the user will work

Kindly sugest

Tags (1)
0 Karma

dkeck
Influencer

Please accept the answer if it helped. Thank you 🙂

0 Karma

lakshman239
Influencer

If the dashboards (views), alerts and reports were in any specific app, you can take the files or the app [ e.g. savedsearches.conf, props.conf] and move them to new instance and it should work.

You just need to ensure the required indexers and other indexer specific settings/requirements are added in the indexer.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...