Installation

Migration of splunk 3.x on Solaris to RHEL 5

stueyb21
New Member

Hi Everyone,

I have been tasked with migrating our main SPLUNK server from a 3.x installation on Solaris (sparc) to 4.1 on RHEL 5.

Now I understand about setting up the log server etc but the reports and configs are quite highly customised and what I want to do is just migrate ALL reports and data gathering tools across onto RHEL.

I have installed 4.1 and have it working (on a base level) RHEL fine. I did a search for migration from sparc to intel and the only thing that got mentioned was db rebuilds. I am quite happy to rebuild the dbs but the reports are many and quite complicated.

I tried copying across the .confs but they dont seem to work 😞 Can anyone suggest how to tackle this. To summerise all I want to do is to transfer whats on the Solaris SPARC to RHEL on Linux. Keep changes to a minimum etc

Tags (2)
0 Karma

rotten
Communicator
  • Don't forget all the etc/users directories too.

Do you have any custom searchscripts? (We always have to update sendemail.py after each upgrade. Back when we ran the Unix app we customized several of those scripts as well.)

Can he copy the saved reports in ${SPLUNK_HOME}/var too, or are those os/install specific?

0 Karma

southeringtonp
Motivator

fyi, you can get around needing to keep replacing sendemail.py. Use a different filename for your local modifications, and update the search app to point to your version instead of the default script. See also - http://answers.splunk.com/questions/6423/how-to-change-default-alert-smtp-port

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

First, you must reindex all your data. You can't get indexes from a SPARC system to work on an Intel system.

Migration is pretty straightforward. What I would do is first upgrade the Solaris system, let the migration scripts do their work, then copy the custom configs (in the "local" subdirectories) of the upgraded Solaris over. The configuration files between Solaris and Linux are identical, if they are of the same version.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...