Installation

How to copy all the users from one existing server to the new server?

jiuan
Explorer

I'm setting up a new Splunk Server on a different OS. Instead of creating all the users manually, how can I copy all the users from existing server to the new server?

Thanks, Jiuan

Labels (1)
Tags (3)

starcher
Influencer

You are getting that error because the passwords for the SSL keys were encrypted under the old splunk.secret. If you copied one from another server the hash no longer works. You need to re-enter the password in the appropriate conf files and let Splunk re-encrypt it.

ridwanahmed
Path Finder

what do you mean in the appropriate conf files?

0 Karma

Stephen_Sorkin
Splunk Employee
Splunk Employee

You should move etc/apps/*/local/... and etc/users/... to capture all user data. The first directory hierarchy brings over shared objects and the second brings over private objects. Additionally you should configure authentication to yield the same set of users.

marco_sulla
Path Finder

You have to copy also the $SPLUNK_HOME/etc/system/local/authorize.conf file if you have one.

0 Karma

nouse66
New Member

I got that SSL error at first also. I fixed it by copying this setting from the other server's etc/system/local/server.conf:
[sslConfig]
sslKeysfilePassword =

0 Karma

jiuan
Explorer

hmmm..... got this error:

ERROR SSLCommon - Can't read key file /home/a478377/workspace/splunk/etc/auth/server.pem

0 Karma

jiuan
Explorer

Thanks, Stephen!

I just talked to Mick about how to copy the authentication too. He mentioned that all I need is copying etc/passwd and etc/auth/splunk.secret.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...