<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't access data after DB migration in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-access-data-after-DB-migration/m-p/17487#M2266</link>
    <description>&lt;P&gt;I backed up all my data, moved it to a larger secondary drive. Uninstalled and re-installed splunk on top of the backed up data on the secondary drive. Now when I search I can not see any data before the backup/install. It's a windows box, and splunk 4.1.3. What can I do?&lt;/P&gt;</description>
    <pubDate>Fri, 16 Jul 2010 00:30:44 GMT</pubDate>
    <dc:creator>antinym</dc:creator>
    <dc:date>2010-07-16T00:30:44Z</dc:date>
    <item>
      <title>Can't access data after DB migration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-access-data-after-DB-migration/m-p/17487#M2266</link>
      <description>&lt;P&gt;I backed up all my data, moved it to a larger secondary drive. Uninstalled and re-installed splunk on top of the backed up data on the secondary drive. Now when I search I can not see any data before the backup/install. It's a windows box, and splunk 4.1.3. What can I do?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2010 00:30:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-access-data-after-DB-migration/m-p/17487#M2266</guid>
      <dc:creator>antinym</dc:creator>
      <dc:date>2010-07-16T00:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access data after DB migration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-access-data-after-DB-migration/m-p/17488#M2267</link>
      <description>&lt;P&gt;Where does your backed up data live and do you have the &lt;CODE&gt;SPLUNK_DB&lt;/CODE&gt; variable set correctly in &lt;CODE&gt;%SPLUNK_HOME\etc\splunk-launch.conf&lt;/CODE&gt;?&lt;/P&gt;

&lt;P&gt;Or do you have your &lt;CODE&gt;$SPLUNK_HOME\etc\system\local\indexes.conf&lt;/CODE&gt; pointing to the backup location?&lt;/P&gt;

&lt;P&gt;Basically what I'm asking is, have you told your new Splunk instance where to find the existing data?  An easy solution would be to just copy all of your index buckets into the &lt;CODE&gt;%SPLUNK_HOME\var\lib\splunk\defaultdb\db&lt;/CODE&gt; directory, assuming it's a brand new instance and you haven't yet made any changes to the files mentioned above.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2010 02:14:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-access-data-after-DB-migration/m-p/17488#M2267</guid>
      <dc:creator>Mick</dc:creator>
      <dc:date>2010-07-16T02:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access data after DB migration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-access-data-after-DB-migration/m-p/17489#M2268</link>
      <description>&lt;P&gt;The %SPLUNK_HOME\etc\splunk-launch.conf is not set. According to the info in the file, it should use the parent directory (D:\splunk) which is where all the files were copied.&lt;/P&gt;

&lt;P&gt;I don't have a $SPLUNK_HOME\etc\system\local\indexes.conf&lt;BR /&gt;
but that directory does exist with other conf files&lt;/P&gt;

&lt;P&gt;I did copy the %SPLUNK_HOME\var\lib\splunk\defaultdb\db first, then uninstalled splunk, and re-installed. My inputs.conf is working, but still no access to the old info.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2010 02:38:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-access-data-after-DB-migration/m-p/17489#M2268</guid>
      <dc:creator>antinym</dc:creator>
      <dc:date>2010-07-16T02:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access data after DB migration</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-t-access-data-after-DB-migration/m-p/17490#M2269</link>
      <description>&lt;P&gt;I can see lots of files and directories in %SPLUNK_HOME\var\lib\splunk\defaultdb\db &lt;/P&gt;

&lt;P&gt;it looks like the following but with different dates and numbers, obviously.&lt;/P&gt;

&lt;P&gt;04/07/2010  09:57 AM    &lt;DIR&gt;          db_1219018015_1219018015_24&lt;BR /&gt;
04/07/2010  09:57 AM                 0 db_1219018015_1219018015_24.sentinel&lt;BR /&gt;
06/05/2010  02:10 PM    &lt;DIR&gt;          db_1223363806_1192723204_31&lt;BR /&gt;
06/05/2010  02:10 PM                 0 db_1223363806_1192723204_31.sentinel&lt;BR /&gt;
04/05/2010  09:41 AM    &lt;DIR&gt;          db_1226784675_1219014387_2&lt;/DIR&gt;&lt;/DIR&gt;&lt;/DIR&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 09:15:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-t-access-data-after-DB-migration/m-p/17490#M2269</guid>
      <dc:creator>antinym</dc:creator>
      <dc:date>2020-09-28T09:15:07Z</dc:date>
    </item>
  </channel>
</rss>

