Splunk Search

how to migrate my saved searches/dashboard/apps from non-cluster to a cluster?

danielwan
Explorer

I have single Splunk instance and would like to migrate to a new search head cluster and the index cluster.

I have a bunch of saved searches/dashboards/apps. is it Ok if I simply copy them to the same directories of each search head members?

0 Karma
1 Solution

hardikJsheth
Motivator

Yes that will work.

One more option is to use search head deployer. Put all the things on your search head deployer under $SPLUNK_HOME/etc/shcluster/ folder. In this case you won't need to do copy on different search heads, instead push it from search head deployer.

In this folder you will have two folders users and apps. Users folder will contain all the custom changes done by different users. You can copy $SPLUNK_HOME/etc/users folder to this folder. For apps you can copy content from $SPLUNK_HOME/etc/apps folder to $SPLUNK_HOME/etc/shcluster/apps folder.

View solution in original post

0 Karma

hardikJsheth
Motivator

Yes that will work.

One more option is to use search head deployer. Put all the things on your search head deployer under $SPLUNK_HOME/etc/shcluster/ folder. In this case you won't need to do copy on different search heads, instead push it from search head deployer.

In this folder you will have two folders users and apps. Users folder will contain all the custom changes done by different users. You can copy $SPLUNK_HOME/etc/users folder to this folder. For apps you can copy content from $SPLUNK_HOME/etc/apps folder to $SPLUNK_HOME/etc/shcluster/apps folder.

0 Karma
Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...