<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk data migration from Splunk cloud to other tool in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746792#M29486</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264857"&gt;@kiran_panchavat&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I challenge that this is either incorrect or missing some context. I appreciate that this is the sort of thing PS get involved with but I know a number of customers who have managed this themselves, as once it is in DDSS it isnt much different to a standard thaw process.&lt;/P&gt;&lt;P&gt;Infact the process is detailed in the public docs (&lt;STRONG&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Admin/DataSelfStorage#:~:text=_audit%22%20action%3Dself_storage_edit-,Restore%20indexed%20data%20from%20a%20self%2Dstorage%20location,-You%20might%20need" target="_self"&gt;Restore indexed data from a self-storage location&lt;/A&gt;&lt;/STRONG&gt;) with a step-by-step process which does not reference requirement for PS.&lt;/P&gt;&lt;P&gt;I created a script to convert DDSS to SmartStore for a customer who wanted a small on-prem SH to be able to access old data which you might find useful&amp;nbsp;&lt;A href="https://github.com/livehybrid/ddss-restore" target="_blank"&gt;https://github.com/livehybrid/ddss-restore&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
    <pubDate>Thu, 22 May 2025 22:42:10 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-05-22T22:42:10Z</dc:date>
    <item>
      <title>Splunk data migration from Splunk cloud to other tool</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746766#M29478</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I just needed some help from Splunk regarding a request from our clients. So, a client is migrating from Splunk to Sentinel but has about 25 TBs of data still on Splunk cloud which they want to keep for at least a year. The data should be readable for investigations and compliance purposes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I know the client might need Splunk professional services for all options mentioned above since it's Splunk Cloud but what would be the best and most cost-effective&amp;nbsp;solution for them? Can you please help and advise what could be the best way forward.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 16:57:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746766#M29478</guid>
      <dc:creator>ssuluguri</dc:creator>
      <dc:date>2025-05-22T16:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk data migration from Splunk cloud to other tool</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746767#M29479</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253157"&gt;@ssuluguri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You mention that the customer wants their data to be readable after moving off Splunk Cloud, does this mean it would need to be in raw format?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The easiest way to get data out of Splunk Cloud from my experience is to use&amp;nbsp;Dynamic Data: Self-Storage (DDSS) - storing frozen buckets into the customer's S3 bucket. Once here you can do a number of things with it:&lt;/P&gt;&lt;P&gt;1) Thaw it out into a Splunk instance with mininal/free license (you wont be ingesting new data)&lt;/P&gt;&lt;P&gt;2) Extract the journal file from the DDSS buckets leaving you with the raw data.&lt;/P&gt;&lt;P&gt;Would the customer be willing to have a small Splunk instance with their archived data in for easy searching?&lt;/P&gt;&lt;P&gt;If it helps, Ive got a repo at&amp;nbsp;&lt;A href="https://github.com/livehybrid/ddss-restore" target="_blank"&gt;https://github.com/livehybrid/ddss-restore&lt;/A&gt;&amp;nbsp;which is primarily for converting DDSS back into SmartStore buckets for use with a semi-offline (in-case of emergencies-style) data storage.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 17:16:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746767#M29479</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-22T17:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk data migration from Splunk cloud to other tool</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746768#M29480</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/253157"&gt;@ssuluguri&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you enables Dynamic Data Self-Storage (DDSS) to export your aged ingested data, the oldest data is moved to the Amazon S3 account in the same region as their Splunk Cloud deployment before it is deleted from the index. You are responsible for AWS payments for the use of the Amazon S3 account. When data is deleted&lt;BR /&gt;from the index, it is no longer searchable by Splunk Cloud.&lt;/P&gt;&lt;P&gt;Customers are responsible for managing DDSS and a non Splunk Cloud stack for searching archived data. This is a manual process and customers will require a professional services engagement.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataSelfStorage" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/DataSelfStorage&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NOTE:&lt;/P&gt;&lt;P&gt;DDSS Data Egress - No limit - Export 1 TB/hr; Must be in the same region as the indexing tier&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/platform/dynamic-data-data-retention-options-in-splunk-cloud.html" target="_blank"&gt;https://www.splunk.com/en_us/blog/platform/dynamic-data-data-retention-options-in-splunk-cloud.html&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 17:30:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746768#M29480</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-05-22T17:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk data migration from Splunk cloud to other tool</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746775#M29482</link>
      <description>&lt;P&gt;Thank you for your advice&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 19:00:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746775#M29482</guid>
      <dc:creator>ssuluguri</dc:creator>
      <dc:date>2025-05-22T19:00:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk data migration from Splunk cloud to other tool</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746784#M29484</link>
      <description>&lt;P&gt;Professional Services is not required to configure or use DDSS.&lt;/P&gt;&lt;P&gt;If you are moving away from Splunk Cloud then a customer can setup DDSS using an sc_admin account via the Web UI and/or ACS and then configure their indexes to use the DDSS location.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To migrate away from Splunk Cloud the customer will then need to reduce the retention on these indexes which will trigger existing buckets from DDAS (Active Searchable) to roll to "frozen" (DDSS).&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point the buckets in S3 are the same as any other frozen bucket from Splunk Enterprise or Splunk Cloud and can be thawed. (see&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.4.2/Indexer/Restorearchiveddata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.4.2/Indexer/Restorearchiveddata&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;If only the raw data is required then this can be extracted from the journal.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 21:48:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746784#M29484</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-22T21:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk data migration from Splunk cloud to other tool</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746790#M29485</link>
      <description>&lt;P&gt;According to the Splunk Cloud Overview Technical Enablement, Splunk recommends engaging Professional Services..&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiran_panchavat_0-1747952840443.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39108iBD904AB0BBFDD4BE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiran_panchavat_0-1747952840443.png" alt="kiran_panchavat_0-1747952840443.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 22:28:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746790#M29485</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-05-22T22:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk data migration from Splunk cloud to other tool</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746792#M29486</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264857"&gt;@kiran_panchavat&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I challenge that this is either incorrect or missing some context. I appreciate that this is the sort of thing PS get involved with but I know a number of customers who have managed this themselves, as once it is in DDSS it isnt much different to a standard thaw process.&lt;/P&gt;&lt;P&gt;Infact the process is detailed in the public docs (&lt;STRONG&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/9.3.2408/Admin/DataSelfStorage#:~:text=_audit%22%20action%3Dself_storage_edit-,Restore%20indexed%20data%20from%20a%20self%2Dstorage%20location,-You%20might%20need" target="_self"&gt;Restore indexed data from a self-storage location&lt;/A&gt;&lt;/STRONG&gt;) with a step-by-step process which does not reference requirement for PS.&lt;/P&gt;&lt;P&gt;I created a script to convert DDSS to SmartStore for a customer who wanted a small on-prem SH to be able to access old data which you might find useful&amp;nbsp;&lt;A href="https://github.com/livehybrid/ddss-restore" target="_blank"&gt;https://github.com/livehybrid/ddss-restore&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 22:42:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746792#M29486</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-05-22T22:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk data migration from Splunk cloud to other tool</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746799#M29492</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906"&gt;@livehybrid&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You're absolutely right that the public documentation (including the &lt;EM&gt;Restore indexed data from a self-storage location&lt;/EM&gt; guide) outlines the DDSS process in detail, and it is technically possible for customers to manage this independently, especially those with in-house Splunk expertise.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 May 2025 02:06:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Splunk-data-migration-from-Splunk-cloud-to-other-tool/m-p/746799#M29492</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-05-23T02:06:25Z</dc:date>
    </item>
  </channel>
</rss>

