<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Script to backup of Splunk in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Script-to-backup-of-Splunk/m-p/52404#M1671</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;This will need some tweeking, but here we go:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;#!/bin/bash&lt;BR /&gt;
SPLUNK="/opt/splunk"&lt;BR /&gt;
CONFIG="/opt/splunk/etc"&lt;BR /&gt;
BUCKETS="/opt/splunk/var/lib/splunk/"&lt;BR /&gt;
ADMU={admin-user-name}&lt;BR /&gt;
ADMP={admin-password}&lt;BR /&gt;
INDEX={index you need to roll}&lt;BR /&gt;
SPLUNK_HOME="/opt/splunk"&lt;BR /&gt;
SPLUNK_DB="/opt/splunk/var/lib/splunk"&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;mount /mnt/backup&lt;BR /&gt;
set $(date)&lt;/P&gt;

&lt;P&gt;for i in &lt;CODE&gt;ls /opt/splunk/var/lib/splunk&lt;/CODE&gt; ; do $SPLUNK_HOME/bin/splunk _internal call $SPLUNK_DB/roll-hot-buckets –auth $ADMU:$ADMP ; done&lt;/P&gt;

&lt;P&gt;if test "$1" = "Sun" ; then&lt;BR /&gt;
        # weekly a full backup of all data and config. settings:&lt;BR /&gt;
        #&lt;BR /&gt;
        tar cfz "/backup/data/data_full_$6-$2-$3.tgz" $BUCKETS –-exclude='&lt;EM&gt;hot_&lt;/EM&gt;' ; done&lt;BR /&gt;
        rm -f /backup/data/data_diff*&lt;BR /&gt;
        #&lt;BR /&gt;
        tar cfz "/backup/config/config_full_$6-$2-$3.tgz" $CONFIG&lt;BR /&gt;
        rm -f /backup/config/config_diff*&lt;BR /&gt;
else&lt;BR /&gt;
        # incremental backup:&lt;BR /&gt;
        #&lt;BR /&gt;
        find $BUCKETS -depth -type f ( -ctime -1 -o -mtime -1 ) -print &amp;gt; $LIST&lt;BR /&gt;
        tar cfzT "/backup/data/data_diff_$6-$2-$3.tgz" "$LIST" –-exclude='&lt;EM&gt;hot_&lt;/EM&gt;' ; done&lt;BR /&gt;
        rm -f "$LIST"&lt;BR /&gt;
        #&lt;BR /&gt;
        find $CONFIG -depth -type f  ( -ctime -1 -o -mtime -1 ) -print &amp;gt; $LIST&lt;BR /&gt;
        tar cfzT "/backup/config/config_diff_$6-$2-$3.tgz" "$LIST"&lt;BR /&gt;
        rm -f "$LIST"&lt;BR /&gt;
fi&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 10:19:15 GMT</pubDate>
    <dc:creator>hedgehog</dc:creator>
    <dc:date>2020-09-28T10:19:15Z</dc:date>
    <item>
      <title>Script to backup of Splunk</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Script-to-backup-of-Splunk/m-p/52403#M1670</link>
      <description>&lt;P&gt;Does anyone have an example of a backup script for Splunk&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2012 14:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Script-to-backup-of-Splunk/m-p/52403#M1670</guid>
      <dc:creator>krissid</dc:creator>
      <dc:date>2012-01-17T14:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: Script to backup of Splunk</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Script-to-backup-of-Splunk/m-p/52404#M1671</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;This will need some tweeking, but here we go:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;#!/bin/bash&lt;BR /&gt;
SPLUNK="/opt/splunk"&lt;BR /&gt;
CONFIG="/opt/splunk/etc"&lt;BR /&gt;
BUCKETS="/opt/splunk/var/lib/splunk/"&lt;BR /&gt;
ADMU={admin-user-name}&lt;BR /&gt;
ADMP={admin-password}&lt;BR /&gt;
INDEX={index you need to roll}&lt;BR /&gt;
SPLUNK_HOME="/opt/splunk"&lt;BR /&gt;
SPLUNK_DB="/opt/splunk/var/lib/splunk"&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;mount /mnt/backup&lt;BR /&gt;
set $(date)&lt;/P&gt;

&lt;P&gt;for i in &lt;CODE&gt;ls /opt/splunk/var/lib/splunk&lt;/CODE&gt; ; do $SPLUNK_HOME/bin/splunk _internal call $SPLUNK_DB/roll-hot-buckets –auth $ADMU:$ADMP ; done&lt;/P&gt;

&lt;P&gt;if test "$1" = "Sun" ; then&lt;BR /&gt;
        # weekly a full backup of all data and config. settings:&lt;BR /&gt;
        #&lt;BR /&gt;
        tar cfz "/backup/data/data_full_$6-$2-$3.tgz" $BUCKETS –-exclude='&lt;EM&gt;hot_&lt;/EM&gt;' ; done&lt;BR /&gt;
        rm -f /backup/data/data_diff*&lt;BR /&gt;
        #&lt;BR /&gt;
        tar cfz "/backup/config/config_full_$6-$2-$3.tgz" $CONFIG&lt;BR /&gt;
        rm -f /backup/config/config_diff*&lt;BR /&gt;
else&lt;BR /&gt;
        # incremental backup:&lt;BR /&gt;
        #&lt;BR /&gt;
        find $BUCKETS -depth -type f ( -ctime -1 -o -mtime -1 ) -print &amp;gt; $LIST&lt;BR /&gt;
        tar cfzT "/backup/data/data_diff_$6-$2-$3.tgz" "$LIST" –-exclude='&lt;EM&gt;hot_&lt;/EM&gt;' ; done&lt;BR /&gt;
        rm -f "$LIST"&lt;BR /&gt;
        #&lt;BR /&gt;
        find $CONFIG -depth -type f  ( -ctime -1 -o -mtime -1 ) -print &amp;gt; $LIST&lt;BR /&gt;
        tar cfzT "/backup/config/config_diff_$6-$2-$3.tgz" "$LIST"&lt;BR /&gt;
        rm -f "$LIST"&lt;BR /&gt;
fi&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:19:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Script-to-backup-of-Splunk/m-p/52404#M1671</guid>
      <dc:creator>hedgehog</dc:creator>
      <dc:date>2020-09-28T10:19:15Z</dc:date>
    </item>
  </channel>
</rss>

