This article explains the procedure to migrate the Sentinel event and raw data with less down time.
Limitation with the current utilities available in Sentinel server:
“Slink Integrator and Slink Action”
Here is the really cool solution to address the migration, the event and raw data problem which we have described above:
Sentinel Event and Raw data Migration:
Slink connector does not store the raw data during this process of migration. Hence, we didn’t recommend the Slink approach to migrate.
In other words, if you forward the events from the source server using Slink Integrator, in the target server you will not see where the respective raw data file is being stored.
In-order to migrate the raw data. Here is the approach.
Ex, Alerts, SI, Netflow with option –i).
Backup in source setup:
./backup_util.sh -c -m backup -f /home/novell/config.tar.gz
Restore in target setup:
./backup_util.sh -m restore -f /home/novell/config.tar.gz
Disclaimer: As with everything else at NetIQ Cool Solutions, this content is definitely not supported by NetIQ, so Customer Support will not be able to help you if it has any adverse effect on your environment. It just worked for at least one person, and perhaps it will be useful for you too. Be sure to test in a non-production environment.