<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What are good backup strategies for indexer buckets? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-are-good-backup-strategies-for-indexer-buckets/m-p/254462#M48857</link>
    <description>&lt;P&gt;What strategies do people use for backups of their buckets? Is there a clean way to identify "new" buckets for a given day based on their file name? &lt;/P&gt;</description>
    <pubDate>Thu, 26 Jan 2017 15:03:08 GMT</pubDate>
    <dc:creator>pdoconnell</dc:creator>
    <dc:date>2017-01-26T15:03:08Z</dc:date>
    <item>
      <title>What are good backup strategies for indexer buckets?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-good-backup-strategies-for-indexer-buckets/m-p/254462#M48857</link>
      <description>&lt;P&gt;What strategies do people use for backups of their buckets? Is there a clean way to identify "new" buckets for a given day based on their file name? &lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 15:03:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-good-backup-strategies-for-indexer-buckets/m-p/254462#M48857</guid>
      <dc:creator>pdoconnell</dc:creator>
      <dc:date>2017-01-26T15:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: What are good backup strategies for indexer buckets?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-good-backup-strategies-for-indexer-buckets/m-p/254463#M48858</link>
      <description>&lt;P&gt;If you have an Hadoop cluster, you might consider Hunk for a full backup solution - &lt;A href="https://answers.splunk.com/answers/411055/is-there-a-solution-to-back-up-splunk-data-into-hd.html"&gt;Is there a solution to back up Splunk data into HDFS to make it available for search via Hunk?&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 15:50:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-good-backup-strategies-for-indexer-buckets/m-p/254463#M48858</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2017-01-26T15:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: What are good backup strategies for indexer buckets?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-good-backup-strategies-for-indexer-buckets/m-p/254464#M48859</link>
      <description>&lt;P&gt;Splunk recommends snapshot technology to backup buckets. Due to hot buckets being written to, you should consider not backing them up via snapshots, as you may miss data. Apart from that, snapshotting all the other buckets is recommended (warm, cold, ...).&lt;/P&gt;

&lt;P&gt;Every bucket follows a naming convention with two timestamps (newest and oldest time):&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.1/Indexer/HowSplunkstoresindexes#Bucket_naming_conventions"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.1/Indexer/HowSplunkstoresindexes#Bucket_naming_conventions&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Did that answer your question?&lt;/P&gt;

&lt;P&gt;Skalli&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 16:34:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-good-backup-strategies-for-indexer-buckets/m-p/254464#M48859</guid>
      <dc:creator>skalliger</dc:creator>
      <dc:date>2017-01-26T16:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: What are good backup strategies for indexer buckets?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-good-backup-strategies-for-indexer-buckets/m-p/254465#M48860</link>
      <description>&lt;P&gt;The documentation recommends doing incremental backups of warm buckets, see &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.2/Indexer/Backupindexeddata"&gt;Back up indexed data&lt;/A&gt; in the &lt;EM&gt;Managing Indexers and Clusters of Indexers&lt;/EM&gt; manual. As skalliger mentions in his answer, the bucket names do indicate the age of the data they contain.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 18:06:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-good-backup-strategies-for-indexer-buckets/m-p/254465#M48860</guid>
      <dc:creator>ChrisG</dc:creator>
      <dc:date>2017-01-26T18:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: What are good backup strategies for indexer buckets?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-good-backup-strategies-for-indexer-buckets/m-p/254466#M48861</link>
      <description>&lt;P&gt;Snapshot makes you get you data backed up for your instant point of time data. So very reason, Splunk recommends to have resiliency to be maintained, in case to protect data&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 01:19:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-good-backup-strategies-for-indexer-buckets/m-p/254466#M48861</guid>
      <dc:creator>anand_singh17</dc:creator>
      <dc:date>2017-02-15T01:19:04Z</dc:date>
    </item>
  </channel>
</rss>

