Splunk Enterprise Security

How to migrate Splunk Enterprise Security from VM to new physical host?


I need to migrate my current ES installation from a VM to a physical host, due to performance issues in the virtual instance. 

Because of internal policies, I cannot simply clone the system via rsync, as the new physical box must have a new name to indicate it isn't a VM.

I tried copying the /opt/splunk/etc/system subdirectory of the new server to a backup location, then using rsync to replicate the /opt/splunk/etc subdirectory structure from the functional VM to the new server. I copied the backup of system back into place, except for the server.conf which I merged the two together.

Tons of errors. Tons of missing data in the ES dashboards.

What am I missing?

Thanks in advance for any suggestions.

Labels (2)
0 Karma


Have you considered fresh ES install on the new physical server and migrate the data from your VM?

0 Karma
Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of Splunk APM’s and Splunk RUM’s streaming infrastructure in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...