Splunk Search

how to migrate my saved searches/dashboard/apps from non-cluster to a cluster?

danielwan
Explorer

I have single Splunk instance and would like to migrate to a new search head cluster and the index cluster.

I have a bunch of saved searches/dashboards/apps. is it Ok if I simply copy them to the same directories of each search head members?

0 Karma
1 Solution

hardikJsheth
Motivator

Yes that will work.

One more option is to use search head deployer. Put all the things on your search head deployer under $SPLUNK_HOME/etc/shcluster/ folder. In this case you won't need to do copy on different search heads, instead push it from search head deployer.

In this folder you will have two folders users and apps. Users folder will contain all the custom changes done by different users. You can copy $SPLUNK_HOME/etc/users folder to this folder. For apps you can copy content from $SPLUNK_HOME/etc/apps folder to $SPLUNK_HOME/etc/shcluster/apps folder.

View solution in original post

0 Karma

hardikJsheth
Motivator

Yes that will work.

One more option is to use search head deployer. Put all the things on your search head deployer under $SPLUNK_HOME/etc/shcluster/ folder. In this case you won't need to do copy on different search heads, instead push it from search head deployer.

In this folder you will have two folders users and apps. Users folder will contain all the custom changes done by different users. You can copy $SPLUNK_HOME/etc/users folder to this folder. For apps you can copy content from $SPLUNK_HOME/etc/apps folder to $SPLUNK_HOME/etc/shcluster/apps folder.

0 Karma
Get Updates on the Splunk Community!

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...