Splunk Enterprise Security

How to migrate Splunk Enterprise Security from VM to new physical host?

discenzadoe
Explorer

I need to migrate my current ES installation from a VM to a physical host, due to performance issues in the virtual instance. 

Because of internal policies, I cannot simply clone the system via rsync, as the new physical box must have a new name to indicate it isn't a VM.

I tried copying the /opt/splunk/etc/system subdirectory of the new server to a backup location, then using rsync to replicate the /opt/splunk/etc subdirectory structure from the functional VM to the new server. I copied the backup of system back into place, except for the server.conf which I merged the two together.

Tons of errors. Tons of missing data in the ES dashboards.

What am I missing?

Thanks in advance for any suggestions.

Labels (2)
0 Karma

lakshman239
Influencer

Have you considered fresh ES install on the new physical server and migrate the data from your VM?

0 Karma
Get Updates on the Splunk Community!

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...