<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send Splunk Archive Logs to Ceph S3 in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Send-Splunk-Archive-Logs-to-Ceph-S3/m-p/546436#M5456</link>
    <description>&lt;UL&gt;&lt;LI&gt;Hmm so it doesn’t look like there’s an easy way for us to automatically copy over the frozen logs directly to the ceph s3 bucket?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Do you have any ideas on how we can write a script to copy over frozen buckets over to ceph s3 buckets?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Apr 2021 20:47:46 GMT</pubDate>
    <dc:creator>splunkuser109</dc:creator>
    <dc:date>2021-04-01T20:47:46Z</dc:date>
    <item>
      <title>Send Splunk Archive Logs to Ceph S3</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Send-Splunk-Archive-Logs-to-Ceph-S3/m-p/546424#M5453</link>
      <description>&lt;P&gt;How can we automatically send frozen/archived splunk logs from the indexers over to a Ceph S3 bucket using the indexers.conf file on the indexers?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 19:20:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Send-Splunk-Archive-Logs-to-Ceph-S3/m-p/546424#M5453</guid>
      <dc:creator>splunkuser109</dc:creator>
      <dc:date>2021-04-01T19:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Send Splunk Archive Logs to Ceph S3</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Send-Splunk-Archive-Logs-to-Ceph-S3/m-p/546431#M5455</link>
      <description>&lt;P&gt;Yes, sort of.&amp;nbsp; Use indexers.conf to specify a coldToFrozenScript.&amp;nbsp; That script, which you must write, will copy the archived buckets to Ceph.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/Indexer/Automatearchiving" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/Indexer/Automatearchiving &lt;/A&gt;and&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.3/Admin/Indexesconf#PER_INDEX_OPTIONS" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.3/Admin/Indexesconf#PER_INDEX_OPTIONS&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 20:12:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Send-Splunk-Archive-Logs-to-Ceph-S3/m-p/546431#M5455</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-01T20:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Send Splunk Archive Logs to Ceph S3</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Send-Splunk-Archive-Logs-to-Ceph-S3/m-p/546436#M5456</link>
      <description>&lt;UL&gt;&lt;LI&gt;Hmm so it doesn’t look like there’s an easy way for us to automatically copy over the frozen logs directly to the ceph s3 bucket?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Do you have any ideas on how we can write a script to copy over frozen buckets over to ceph s3 buckets?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 20:47:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Send-Splunk-Archive-Logs-to-Ceph-S3/m-p/546436#M5456</guid>
      <dc:creator>splunkuser109</dc:creator>
      <dc:date>2021-04-01T20:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: Send Splunk Archive Logs to Ceph S3</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Send-Splunk-Archive-Logs-to-Ceph-S3/m-p/546462#M5458</link>
      <description>&lt;P&gt;Personally, I like Visual Studio Code, but notepad++ is good, too.&amp;nbsp;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2021 00:42:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Send-Splunk-Archive-Logs-to-Ceph-S3/m-p/546462#M5458</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-02T00:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Send Splunk Archive Logs to Ceph S3</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Send-Splunk-Archive-Logs-to-Ceph-S3/m-p/546463#M5459</link>
      <description>&lt;P&gt;hahaha. Can remotePath (ceph s3 bucket) not be used to store the cold or frozen buckets/logs?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/Indexesconf" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/Indexesconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2021 03:03:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Send-Splunk-Archive-Logs-to-Ceph-S3/m-p/546463#M5459</guid>
      <dc:creator>splunkuser109</dc:creator>
      <dc:date>2021-04-02T03:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Send Splunk Archive Logs to Ceph S3</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Send-Splunk-Archive-Logs-to-Ceph-S3/m-p/546527#M5464</link>
      <description>&lt;P&gt;remotePath is used for warm/cold buckets.&amp;nbsp; This is part of the SmartStore feature.&amp;nbsp; Frozen buckets are different and are not stored by SmarStore.&lt;/P&gt;&lt;P&gt;There is an example coldToFrozenScript in $SPLUNK_HOME/bin.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2021 12:23:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Send-Splunk-Archive-Logs-to-Ceph-S3/m-p/546527#M5464</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-04-02T12:23:34Z</dc:date>
    </item>
  </channel>
</rss>

