Splunk Search

how to migrate my saved searches/dashboard/apps from non-cluster to a cluster?

danielwan
Explorer

I have single Splunk instance and would like to migrate to a new search head cluster and the index cluster.

I have a bunch of saved searches/dashboards/apps. is it Ok if I simply copy them to the same directories of each search head members?

0 Karma
1 Solution

hardikJsheth
Motivator

Yes that will work.

One more option is to use search head deployer. Put all the things on your search head deployer under $SPLUNK_HOME/etc/shcluster/ folder. In this case you won't need to do copy on different search heads, instead push it from search head deployer.

In this folder you will have two folders users and apps. Users folder will contain all the custom changes done by different users. You can copy $SPLUNK_HOME/etc/users folder to this folder. For apps you can copy content from $SPLUNK_HOME/etc/apps folder to $SPLUNK_HOME/etc/shcluster/apps folder.

View solution in original post

0 Karma

hardikJsheth
Motivator

Yes that will work.

One more option is to use search head deployer. Put all the things on your search head deployer under $SPLUNK_HOME/etc/shcluster/ folder. In this case you won't need to do copy on different search heads, instead push it from search head deployer.

In this folder you will have two folders users and apps. Users folder will contain all the custom changes done by different users. You can copy $SPLUNK_HOME/etc/users folder to this folder. For apps you can copy content from $SPLUNK_HOME/etc/apps folder to $SPLUNK_HOME/etc/shcluster/apps folder.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...