<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem restoring and viewing historical data in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Problem-restoring-and-viewing-historical-data/m-p/707540#M21209</link>
    <description>&lt;P&gt;You don't have to make up your own process for reading historical data - Splunk has documentation for that.&amp;nbsp; See &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.0/Indexer/Restorearchiveddata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.0/Indexer/Restorearchiveddata&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Dec 2024 16:27:28 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2024-12-24T16:27:28Z</dc:date>
    <item>
      <title>Problem restoring and viewing historical data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Problem-restoring-and-viewing-historical-data/m-p/707537#M21208</link>
      <description>&lt;P&gt;Hello everyone&lt;BR /&gt;I currently have a cluster of 2 indexes and also 1 search header mounted on Linux and everything is going well with it, these days what I need is to restore indexed data from 1 year ago, which I have on a disk mounted on the server, I am trying to be able to view that data from my header, but I can't do it, I have done tests like the following:&lt;/P&gt;&lt;P&gt;-I have created a new index called mydb2, so as not to alter my original index (mydb), and I have copied several of the directories that have this name "db_1711654894_1711568541_1281_6C91679A-EBBC-4F09-A710-1CC8C8CA8FDC" to the $SPLUNK_DB/mydb2/db/ directory, when doing this I was not successful&lt;/P&gt;&lt;P&gt;-From the cluster I restarted the 2 indexes, and it didn't work either, but after 2 days, data began to appear, but only the data corresponding to 4 days, however the data directories that I copied to $SPLUNK_DB/mydb2/db/ are several and correspond to 5 months, more days have passed, and I have restarted, and no more data has appeared&lt;/P&gt;&lt;P&gt;Does anyone in the community have knowledge of this? To know how to view historical data that has been restored from a backup&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2024 15:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Problem-restoring-and-viewing-historical-data/m-p/707537#M21208</guid>
      <dc:creator>cyrus18</dc:creator>
      <dc:date>2024-12-24T15:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: Problem restoring and viewing historical data</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Problem-restoring-and-viewing-historical-data/m-p/707540#M21209</link>
      <description>&lt;P&gt;You don't have to make up your own process for reading historical data - Splunk has documentation for that.&amp;nbsp; See &lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.0/Indexer/Restorearchiveddata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.0/Indexer/Restorearchiveddata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Dec 2024 16:27:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Problem-restoring-and-viewing-historical-data/m-p/707540#M21209</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2024-12-24T16:27:28Z</dc:date>
    </item>
  </channel>
</rss>

