Notifications
Clear all
Topic starter
20/07/2026 8:11 pm
We're planning our migration from on-prem Splunk ES to Splunk Cloud (ES SaaS). Our on-prem setup is heavily customized, with a lot of custom correlation searches and data integrations.
I'm curious about the deployment pitfalls others have hit. Specifically, the transition of custom content and managing the hybrid search head during the cutover seems tricky. How did you handle migrating custom correlation searches, data models, and lookups without breaking existing detections? Any gotchas with the Cloud Migrator tool?
Also, how does the operational tempo change? I'm used to pushing configs via Git/Ansible to the on-prem deployment server. The cloud pipeline feels different.
Automate everything.