Installation

Migrate Splunk install from Win2003 32b to a new Win2008R2 64b server

juank
Engager

I need to move my Splunk install from one server to another... What's is the procedure to backup the configuration/indexes, etc to restore in the new server...? I can't find any documentation about it.

Thanks!

Tags (2)

Ledio_Ago
Splunk Employee
Splunk Employee

Another idea is to install Splunk fresh in your Win2k8 64bit box. Stop sending data to the 32bit box. Then:

Option 1: Copy folders var and etc from the old box to the new box. Make sure that the file permissions are the same. Hopefully these boxes belong to a DC so that you can login as the same domain user in both boxes when you copy the files over. You also you'll need to copy your splunk license file over to the new box.

Option 2: Setup these two boxes as a distributed Splunk deployment, with two indexers, your old box and the new one. If you make the old box the Search Head, then you'll have old data and configs, plus your new data will be in the new box.

Copying data around it's little tricky with windows, give the file permissions and all.

0 Karma

piebob
Splunk Employee
Splunk Employee

there is documentation on backing up index and configuration data here:

http://www.splunk.com/base/Documentation/latest/Admin/Whatyoucanbackup

as long as both your 32-bit and 64-bit systems are x86, then you should be ok moving your indexed data.

http://www.splunk.com/base/Documentation/latest/Admin/Moveanindex

it would be useful to have a topic that specifically addressed the overall task of moving a Splunk installation from one machine to another, i will make sure that happens.

gkanapathy
Splunk Employee
Splunk Employee
0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...