<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to restore logs from frozen bucket? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/448066#M77914</link>
    <description>&lt;P&gt;Thank you so much. In the indexes.conf file, I have:&lt;BR /&gt;
[wineventlog]&lt;BR /&gt;
homePath   = volume:primary/wineventlog/db&lt;BR /&gt;
coldPath   = volume:cold/wineventlog/colddb&lt;BR /&gt;
thawedPath = $SPLUNK_DB/wineventlog/thaweddb&lt;BR /&gt;
frozenTimePeriodInSecs = 5768000 (~67 days)&lt;BR /&gt;
For some reasons, I don't see any files in the colddb folder older than 45 days. Do you know what caused the issue and what I need to do if I need to keep the log for 180 days?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;</description>
    <pubDate>Thu, 15 Aug 2019 16:27:55 GMT</pubDate>
    <dc:creator>vnguyen46</dc:creator>
    <dc:date>2019-08-15T16:27:55Z</dc:date>
    <item>
      <title>How to restore logs from frozen bucket?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/448064#M77912</link>
      <description>&lt;P&gt;Hi - in frozen\index\colddb, I have the following files (db_ and rb_)&lt;BR /&gt;
[splunk@spkpnxl1 wineventlog]$ cd colddb&lt;BR /&gt;
[splunk@spkpnxl1 colddb]$ ls&lt;BR /&gt;
db_1564149292_1564145928_6839_1741185A-25EA-4E95-9BBD-447DB7D77D6E&lt;BR /&gt;
rb_1564419759_1564416947_13512_E3EF5E9B-B5C5-4352-B9DA-61B24C683D2B&lt;/P&gt;

&lt;P&gt;How can I restore/re-thaw these files?&lt;BR /&gt;
Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:44:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/448064#M77912</guid>
      <dc:creator>vnguyen46</dc:creator>
      <dc:date>2020-09-30T01:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to restore logs from frozen bucket?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/448065#M77913</link>
      <description>&lt;P&gt;Copy the bucket(s) into the appropriate thaweddb directory, as specified in indexes.conf.  Then run the &lt;CODE&gt;splunk rebuild&lt;/CODE&gt; command on the indexer.  You don't need to worry about the rb_* buckets as they're replicates of buckets stored elsewhere.&lt;BR /&gt;
See &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Restorearchiveddata#Thaw_a_4.2.2B_archive" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.1/Indexer/Restorearchiveddata#Thaw_a_4.2.2B_archive&lt;/A&gt; for details.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:44:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/448065#M77913</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-30T01:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to restore logs from frozen bucket?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/448066#M77914</link>
      <description>&lt;P&gt;Thank you so much. In the indexes.conf file, I have:&lt;BR /&gt;
[wineventlog]&lt;BR /&gt;
homePath   = volume:primary/wineventlog/db&lt;BR /&gt;
coldPath   = volume:cold/wineventlog/colddb&lt;BR /&gt;
thawedPath = $SPLUNK_DB/wineventlog/thaweddb&lt;BR /&gt;
frozenTimePeriodInSecs = 5768000 (~67 days)&lt;BR /&gt;
For some reasons, I don't see any files in the colddb folder older than 45 days. Do you know what caused the issue and what I need to do if I need to keep the log for 180 days?&lt;/P&gt;

&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 16:27:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/448066#M77914</guid>
      <dc:creator>vnguyen46</dc:creator>
      <dc:date>2019-08-15T16:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to restore logs from frozen bucket?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/448067#M77915</link>
      <description>&lt;P&gt;This should be a separate question.&lt;BR /&gt;
Once Splunk freezes a bucket it no longer will do anything with it.  It's up to you to manage the frozen buckets so they remain available for the desired time.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 16:57:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/448067#M77915</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-08-15T16:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to restore logs from frozen bucket?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/448068#M77916</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 17:46:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/448068#M77916</guid>
      <dc:creator>vnguyen46</dc:creator>
      <dc:date>2019-08-15T17:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to restore logs from frozen bucket?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/623513#M107277</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;how do I run the rebuild command for multiple files?&lt;/P&gt;&lt;P&gt;I'm trying to rebuild the logs for 3 months, and I have hundreds of files, instead of running the rebuild&amp;nbsp;command for each file one by one, is there any other way to run bulk? maybe wildcard or something?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2022 01:21:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/623513#M107277</guid>
      <dc:creator>kvm</dc:creator>
      <dc:date>2022-12-07T01:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to restore logs from frozen bucket?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/623574#M107283</link>
      <description>&lt;P&gt;Write a script to rebuild the files.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2022 13:31:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-restore-logs-from-frozen-bucket/m-p/623574#M107283</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2022-12-07T13:31:21Z</dc:date>
    </item>
  </channel>
</rss>

