I have a single search head, so I want to migrate the data to another single search head. I have done this much process till now.
Steps:-
1. Stop Splunk on both instances.
2. Types of objects to migrate
- copy etc/apps folder from the old search head to the new search head.
- copy etc/users private user configuration from the old search head to the new search head
3. Restart the new search head.
Can I run the servers in tandem and slowly cut over while migrating?
... View more