Splunk Enterprise Security

Can you help us migrate Splunk Enterprise to Splunk Cloud?

anandhalagarasa
Path Finder

Hi Team,

Recently, we have purchased Splunk Cloud for our organization. And currently we have all of our setup in our On-Prem environment (Splunk Enterprise), so we want to migrate those instances from Splunk Enterprise to Splunk Cloud.

All the client machines have been already installed with universal forwarders and it's currently reporting to Splunk Enterprise On-Prem Environment.

So what would be the recommended process to migrate those server logs into Splunk Cloud? And also, we want to know how to migrate all apps , dashboards, event types, field extractions and so on.

0 Karma

sarif_splunk
Splunk Employee
Splunk Employee

Apps would require some prep/consideration depending on the apps and the version of Splunk Enterprise you're running. as dkeck has suggested, its best to speak to your Splunk Account Manager/After Sales Engineer to put in place a proper plan.

0 Karma

dkeck
Influencer

Hi good morning,

I would guess this is something that would be done by professional services.

Have a look at this user experiences https://answers.splunk.com/answers/690971/how-do-you-migrate-historic-data-from-on-prem-splu.html

In docs it says

Do not attempt to migrate a Splunk
Enterprise installation to Splunk
Cloud using these instructions. Doing
so could result in data loss. Speak
with Professional Services or your
Splunk Cloud representative for
information and instructions.
https://docs.splunk.com/Documentation/Splunk/7.2.3/Installation/MigrateaSplunkinstance

dkeck
Influencer

If this helped please accept the answer 🙂

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...