Thank you for providing the detailed procedure. Couple of questions:- 1. When you migrated Splunk Enterprise to new servers, did you just copy/paste the configs. SHC(OLD) to SHC(NEW), Indexer(OLD) to Indexer(New) etc and then install Splunk over it OR first install Splunk and then copy/paste OR created a new CM,SHC,Indexer just like a new architect and copy the configs. 2. You mentioned no user was impacted so did you managed to complete the activity same day ? 3. I believe you have updated the Splunk forwarders to point to the indexers just after the activity. It seems while you migrated instance one by one you made sure that Splunk is able to communicate with CM(NEW) and SHC/INDEXER(OLD). Is it correct understanding ? Thanks.
... View more