Well... there are two possible approaches to migration of such environment. First is as you want to do it - swap "one for one" leaving the same addresses, names and so on. You might get away with mo...
See more...
Well... there are two possible approaches to migration of such environment. First is as you want to do it - swap "one for one" leaving the same addresses, names and so on. You might get away with moving whole splunk installation from one server to another and pretending nothing changed but that might be tricky depending on your data layout and - you don't have much room for error - you replace the machine and it must be working perfectly OK. Otherwise it's very hard to diagnose/fix. Another way, at least with some components (clustered indexers, clustered search heads, possibly HFs) would be to deploy new component, add it to environment, migrate data if applicable, decomission old one.