Splunk Search

how to migrate my saved searches/dashboard/apps from non-cluster to a cluster?

danielwan
Explorer

I have single Splunk instance and would like to migrate to a new search head cluster and the index cluster.

I have a bunch of saved searches/dashboards/apps. is it Ok if I simply copy them to the same directories of each search head members?

0 Karma
1 Solution

hardikJsheth
Motivator

Yes that will work.

One more option is to use search head deployer. Put all the things on your search head deployer under $SPLUNK_HOME/etc/shcluster/ folder. In this case you won't need to do copy on different search heads, instead push it from search head deployer.

In this folder you will have two folders users and apps. Users folder will contain all the custom changes done by different users. You can copy $SPLUNK_HOME/etc/users folder to this folder. For apps you can copy content from $SPLUNK_HOME/etc/apps folder to $SPLUNK_HOME/etc/shcluster/apps folder.

View solution in original post

0 Karma

hardikJsheth
Motivator

Yes that will work.

One more option is to use search head deployer. Put all the things on your search head deployer under $SPLUNK_HOME/etc/shcluster/ folder. In this case you won't need to do copy on different search heads, instead push it from search head deployer.

In this folder you will have two folders users and apps. Users folder will contain all the custom changes done by different users. You can copy $SPLUNK_HOME/etc/users folder to this folder. For apps you can copy content from $SPLUNK_HOME/etc/apps folder to $SPLUNK_HOME/etc/shcluster/apps folder.

0 Karma
Get Updates on the Splunk Community!

Wrapping Up Cybersecurity Awareness Month

October might be wrapping up, but for Splunk Education, cybersecurity awareness never goes out of season. ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

What's New in Splunk Observability - October 2025

What’s New?    We’re excited to announce the latest enhancements to Splunk Observability Cloud and share ...