<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Data restore in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Data-restore/m-p/673462#M2716</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi Folks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I wanted to restore a chunk of a data (jan 2023-aug 2023) from a specific index, we do use splunk cloud and use splunk's restore services.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;total size of data from jan to aug: &amp;gt;1700GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;our licensee : 800 GB per day&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;will splunk reindex those data??&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;should I do in chunk??&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm aware of the limitation of 10% of total archive (I'm very new to splunk tough,So correct me.)&lt;/SPAN&gt;&lt;SPAN&gt;WHAT WOULD BE WAY TO GO?&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 07 Jan 2024 17:23:32 GMT</pubDate>
    <dc:creator>vishenps</dc:creator>
    <dc:date>2024-01-07T17:23:32Z</dc:date>
    <item>
      <title>Data restore</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Data-restore/m-p/673462#M2716</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Folks,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I wanted to restore a chunk of a data (jan 2023-aug 2023) from a specific index, we do use splunk cloud and use splunk's restore services.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;total size of data from jan to aug: &amp;gt;1700GB&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;our licensee : 800 GB per day&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;will splunk reindex those data??&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;should I do in chunk??&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm aware of the limitation of 10% of total archive (I'm very new to splunk tough,So correct me.)&lt;/SPAN&gt;&lt;SPAN&gt;WHAT WOULD BE WAY TO GO?&lt;/SPAN&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jan 2024 17:23:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Data-restore/m-p/673462#M2716</guid>
      <dc:creator>vishenps</dc:creator>
      <dc:date>2024-01-07T17:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: Data restore</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Data-restore/m-p/673468#M2717</link>
      <description>&lt;P&gt;If you use Splunk Auto Archive (DDAA) service then it will take 10 days to restore all 1.7TB of data.&amp;nbsp; Each chunk restored remains searchable for 30 days so you'll have only 20 during which the whole thing can be searched.&amp;nbsp; Restored data is treated much the same as thawed data in that it is indexed and searchable, but is not subject to the index retention time.&amp;nbsp; Splunk Cloud automatically removes the restored after 30 days.&amp;nbsp; See &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.1.2308/Admin/DataArchiver#Restore_archived_data_to_Splunk_Cloud_Platform" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.1.2308/Admin/DataArchiver#Restore_archived_data_to_Splunk_Cloud_Platform&lt;/A&gt; for details.&lt;/P&gt;&lt;P&gt;If you use Splunk's Self Service archive (DDSS) then the data must be restored to an on-prem (or private cloud) instance much the same way you would restore frozen data in Splunk Enterprise.&amp;nbsp; There are no time limits for restored DDSS data.&amp;nbsp; See &lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.1.2308/Admin/DataSelfStorage#Restore_indexed_data_from_a_self_storage_location" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.1.2308/Admin/DataSelfStorage#Restore_indexed_data_from_a_self_storage_location&lt;/A&gt; for more.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 00:57:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Data-restore/m-p/673468#M2717</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-01-08T00:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Data restore</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Data-restore/m-p/673471#M2718</link>
      <description>&lt;P&gt;Where did you get this 22 days value? I didn't find anything about restore rate limitation. Only that 10% of the overall storage entitlement. So if the OP has 800GB ingest subscription it includes 90 days of storage by default which translates to ability to restore up to 7.2TB of data at any given point in time if I understand it correctly.&lt;/P&gt;&lt;P&gt;(I'm not a Cloud expert, that's what I understand from Splunk websites so if I'm wrong feel free to correct me)&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jan 2024 22:23:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Data-restore/m-p/673471#M2718</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2024-01-07T22:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: Data restore</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Data-restore/m-p/673475#M2719</link>
      <description>&lt;P&gt;Yeah, I messed that up.&amp;nbsp; I took 10% of the license rather than of the stored data.&amp;nbsp; I'll fix the post.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jan 2024 00:57:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Data-restore/m-p/673475#M2719</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-01-08T00:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Data restore</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Data-restore/m-p/675409#M2767</link>
      <description>&lt;P&gt;&lt;EM&gt;"should I do in chunk"? -&lt;/EM&gt; Yes, use the date ranges to reduce your date range and restore in multiple chunks.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;No it will not "reindex it" -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.1.2308/Admin/DataArchiver#Restore_archived_data_to_Splunk_Cloud_Platform" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/9.1.2308/Admin/DataArchiver#Restore_archived_data_to_Splunk_Cloud_Platform&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You can use the "check size" button to make sure your span is under your entitlement. Remember Dynamic Data Active Archive (DDAA)&amp;nbsp; it is 10% of your Dynamic Data Active Searchable (DDAS), NOT your daily ingest entitlement. Check "cloud monitoring console&amp;gt; license usage &amp;gt; storage summary"&lt;BR /&gt;&lt;BR /&gt;Span too wide! too many buckets!:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mattymo_0-1706199377306.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29090i54D5722EF9940222/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mattymo_0-1706199377306.png" alt="mattymo_0-1706199377306.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;shorten the span, now i can restore!:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mattymo_0-1706199687283.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/29091i92398EB73D0CED34/image-size/medium?v=v2&amp;amp;px=400" role="button" title="mattymo_0-1706199687283.png" alt="mattymo_0-1706199687283.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;reduce your chunk size to under your limit, restore that data, search it, then in the table below you can clear it and restore you next chunk.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Data quality matters here, as if your timestamps are all over the place it can be suprizing how many buckets you have to restore to bring back any give date.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;it will not take multiple days to restore this. if you just shrink your window you can do it in steps.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;restore &amp;gt; search (tip use collect command to help move what you want to another index) &amp;gt; clear restore &amp;gt; repeat&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 16:29:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Data-restore/m-p/675409#M2767</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2024-01-25T16:29:27Z</dc:date>
    </item>
  </channel>
</rss>

