Splunk Search

Migration Issue

Amandeepsin
New Member

We are about to migrate stuff from one cloud env to AWS.. set up is done.. issue is :

  • we have old splunk instance where indexer and search head was on same server.
  • Now, we have segregated the search head and indexer.
  • I want to migrate all the dashboards, alerts, reports to new instance..
  • main issue is :
  • I cannot copy as it is by following migration as stated in splunk because previously we have splunk search head and indexer on same server. Now, we have two instances simply copy and paste will not work
  • Secondly, on old splunk instance we have user on splunk, now we have configured SAML. I don't know If simply copy and paste of the user will work

Kindly sugest

Tags (1)
0 Karma

dkeck
Influencer

Please accept the answer if it helped. Thank you 🙂

0 Karma

lakshman239
Influencer

If the dashboards (views), alerts and reports were in any specific app, you can take the files or the app [ e.g. savedsearches.conf, props.conf] and move them to new instance and it should work.

You just need to ensure the required indexers and other indexer specific settings/requirements are added in the indexer.

0 Karma
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Your Voice Matters! Help Us Shape the New Splunk Lantern Experience

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Building Momentum: Splunk Developer Program at .conf25

At Splunk, developers are at the heart of innovation. That’s why this year at .conf25, we officially launched ...