I am currently creating a new instance on a new server of Splunk. I would like to migrate all of the created items such as views, dashboards, searches, users, etc over. What is the best way to handle this?
This is incorrect:
"Your users would be in /etc/users/."
It should read:
"Your users would be in $SPLUNK_HOME/etc/users/."
If you were to copy the $SPLUNK_HOME/splunk/etc/apps/ folder from the old indexer to the new one, your views and saved searches should be copied over as well, for the applications in question. Make sure to review the permissions to ensure that they are correct on the new indexer. Your users would be in /etc/users/.
Some useful information can also be found here:
http://www.splunk.com/wiki/Deploy:Migrating_a_Splunk_Install