Hello!
This is my situation. I have my main Splunk server on EC2 AWS and I'm trying to move it to a local machine. I cannot lose any data and I only have a couple of days to do it.
I've installed Splunk on my local environment and following this guides [1] and [2], I already copied the data on $splunk_home/etc/apps and $splunk_home/etc/users to the local splunk instalation. So when I open it on the webbrowser, I do see my app, but empty. I know this means that I didn't copy the databases.
But, which DB's or files do I need to copy from Splunk in AWS in order to see my entire data on local with working searches, indexes and all that stuff? I'm not finding any way to do it.
Thanks in advance!
[1] http://answers.splunk.com/answers/138710/splunk-migration-to-another-server.html
[2] http://wiki.splunk.com/Deploy:Migrating_a_Splunk_Install
... View more