Hi I must agree with @PickleRick that this is something where you should hire experienced splunk consultant with good knowledge of infra part too. You definitely need someone to help you! There are...
See more...
Hi I must agree with @PickleRick that this is something where you should hire experienced splunk consultant with good knowledge of infra part too. You definitely need someone to help you! There are lot of missing information which are needed to help you to chose the correct path to do this. At least we are needing the next are you now on onprem with hardware or some virtual environment are you on cloud AWS, Azure, GCP what is your target platform (still onprem with HW, virtual some cloud) are those S3 bucket in onprem, AWS or somewhere else what kind of connectivity you have between splunk server and S3 If you must do this by yourself w/o help by experience splunk consultant, I probably try the next approach, but this definitely depends on answers to above questions. set up additional server with new OS but with current splunk version migrate current splunk installation into it (e.g. https://community.splunk.com/t5/Deployment-Architecture/Splunk-Migration-from-existing-server-to-a-new-server/m-p/681647) update it to the target splunk version add a new SH to use it and migrate (move) SH side apps into it add a new Cluster master and copy indexer side apps & TAs into it's manager_apps add migrated node as 1st indexers into it add 2nd (and maybe 3rd) nodes as additional indexers into it If and only if you have enough fast storage network for S3 buckets, then you could enable smart store into this cluster If above is working without issues. Then stop original standalone instance and start production migration from scratch as you have proven that your test is working and you have step by step instructions how to do it. After you have done your real production migration change UFs and other sources to send events to this new environment. r. Ismo