All, just need some advice. We have a customer that we are migrating across different cloud providers. Their current Splunk cluster is running on Ubuntu 20.04 (which goes end of life 31st of May). We want to add new nodes in the new cloud provider running on RHEL 9.x and extend the existing Splunk cluster. So for a shortwhile we will have a mix of Ubuntu and RHEL nodes running together in the same cluster. Splunk have said this is doable but not something they can guarantee as they are not responsible for the OS running on the cluster nodes. Below is the below migration plan we are proposing to the customer, once we get approval we will deploy a PoC to test the migration approach: 1. Ensure there is low latency and sufficient bandwidth between the two cloud providers 2. Deploy new RHEL nodes in new Cloud provider with the same version of Splunk 3. Add the RHEL nodes to the existing Ubuntu cluster and let the cluster synchronize the data to the new RHEL nodes 4. Following successful data synchronization and testing, the master cluster role will be transferred to one of the RHEL nodes 5. Finally, after a period of co-existence and validation, the existing Ubuntu nodes will be removed from the cluster (indexers and Search heads). Any help or guidance appreciated.
... View more