I would like to set up a 2 node Splunk implementation: 1 Indexer and 1 Search Head. The indexer will hold all roles accept for Search. Search head will do search + house ITSI.
Instead of having to manually set up the LDAP configs, user roles, is there a way to copy the configs (say from original server which will now just be the indexer) and then just copy a certain set of config files over to the Search head? That way I'm not duplicating efforts.
Same goes for Reports, Dashboards, Field extractions, tags, look up fields etc.. Right now I've been using 1 box (stand alone) however I don't want to have to recreate everything on the new search head in order to be functional. I also have ITSI installed on this one stand alone box.. It would be hell on earth if I had to manually set all that up again on the New Search head
What's the proper way to copy settings/ configurations needed to easily expand out without making manual edits.
Thank you
↧