I am looking to move my Splunk EN 7.1.3 installation from Ubuntu to Centos distro.
Referencing Splunk doc on the topic, the suggestion is to:
1. copy the contents of the original splunk $splunk_home (I am assuming default is /opt/splunk) to the new machine
2. install the same version of splunk.
3. confirm indexes.conf contains correct location and path specification for any non-default indexes.
A couple of q's please:
-Do I need to worry about bucket ID conflicts in the above?
-What is the location of the 'indexes.conf' files that I need to check? Is it the '$SPLUNK_HOME/etc/system/local' or '$SPLUNK_HOME/etc/apps/XXX/local', or both?
-Do I need to re-install any of the apps on the new instance, or do apps get copied over in step (1) above?
-Any other caveat I should be aware of? I.e. server cert, license etc?