Deployment Architecture

Urgently move Splunk data from AWS to local today

m0scuni0n
New Member

Hello!

This is my situation. I have my main Splunk server on EC2 AWS and I'm trying to move it to a local machine. I cannot lose any data and I only have a couple of days to do it.

I've installed Splunk on my local environment and following this guides [1] and [2], I already copied the data on $splunk_home/etc/apps and $splunk_home/etc/users to the local splunk instalation. So when I open it on the webbrowser, I do see my app, but empty. I know this means that I didn't copy the databases.

But, which DB's or files do I need to copy from Splunk in AWS in order to see my entire data on local with working searches, indexes and all that stuff? I'm not finding any way to do it.

Thanks in advance!

[1] http://answers.splunk.com/answers/138710/splunk-migration-to-another-server.html
[2] http://wiki.splunk.com/Deploy:Migrating_a_Splunk_Install

0 Karma

Splunker
Communicator

For indexes you'd want $SPLUNK_HOME/var/lib/splunk and all it's sub-directories.

For configs (including the definitions of indexes, apps, includes all user definitions, etc etc..) you'd want $SPLUNK_HOME/etc

Where $SPLUNK_HOME is usually /opt/splunk, but not always. Make sure Splunk is stopped when copying or moving it's files!

At a high-level thats how you'd transfer a Splunk installation, minus the binaries, with a lot of detail glossed over in the interest of brevity.

Hope it helps 🙂

Cheers.

0 Karma
Get Updates on the Splunk Community!

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...