Installation

How can I restore only my Splunk configuration on another server in another location?

paul_DLB
New Member

hi,

I want to test if I can restore only my configuration of my splunk server (indexer and forwarder). I don't want to restore all my data because i don't have enough disk space available.

My original location of splunk is d:\splunk, d:\splunk_data, d:\splunk_archive.

The new server has a different name and the location is c:\splunk.

I follow these steps :

  1. copy d:\splunk\etc (backup of splunk config)
  2. install new splunk (same version) on new server (with different server name)
  3. copy backup files to new server in c:\splunk\etc
  4. restart splunk

But this is not working.
Probably because my splunk installation is now on my c-drive and my server name is not the same. Can I simply change this to the new environment ?
Do I also need to restore the data (d:\splunk_data) to test if my new splunk is working ?

Is there a simple procedure to do this ?

thanks

Labels (1)
0 Karma
1 Solution

MuS
Legend

Hi paul_DLB,

take the docs about How to migrate as example http://docs.splunk.com/Documentation/Splunk/6.2.0/Installation/MigrateaSplunkinstance#How_to_migrate
This way all the needed config files will be changed/adapted to the new server.

hope this helps ...

cheers, MuS

View solution in original post

MuS
Legend

Hi paul_DLB,

take the docs about How to migrate as example http://docs.splunk.com/Documentation/Splunk/6.2.0/Installation/MigrateaSplunkinstance#How_to_migrate
This way all the needed config files will be changed/adapted to the new server.

hope this helps ...

cheers, MuS

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...