Hi @Hudond, I agree with @richgalloway . Only one additional information: if you're using Windows, don't copy the entire $SPLUNK_HOME folder, but install the same Splunk version on the new machine (with a different hostname and ip address). then you can follow the procedure, but copying only $SPLUNK_HOME\etc folder (not the entire $SPLUNK_HOME folder), where Splunk stores all its configurations. On Linux you can copy the entire folder, but on Windows it isn't sufficient. Then at the end, you have to change the License master Addressing on your Indexers, so summarizing: Install Splunk Enterprise on the new server. Stop Splunk Enterprise services on the host from which you want to migrate. Copy the entire contents of the $SPLUNK_HOME\etc directory from the old host to the new host. Start Splunk Enterprise on the new instance. Log into Splunk Enterprise with your existing credentials. After you log in, confirm that your data is intact by searching it. Change the License Master addresses on your Indexers. Ciao. Giuseppe
... View more