<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Smartstore : Bucket status in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Smartstore-Bucket-status/m-p/545435#M90942</link>
    <description>&lt;P&gt;Hot buckets roll to warm when the indexer *starts*, not when it stops.&lt;/P&gt;&lt;P&gt;To upload your data to S2 before stopping, use these steps.&amp;nbsp; They're just my opinion, not based on anything official.&lt;/P&gt;&lt;P&gt;1) Put the indexers into detention.&amp;nbsp; This stops incoming data and prevents new hot buckets.&lt;/P&gt;&lt;P&gt;2) Manually roll each index.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Backupindexeddata#Rolling_buckets_manually_from_hot_to_warm" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Backupindexeddata#Rolling_buckets_manually_from_hot_to_warm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;3) Wait for the buckets to upload.&lt;/P&gt;&lt;P&gt;4) Stop the indexers using &lt;FONT face="courier new,courier"&gt;splunk stop&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Mar 2021 15:43:37 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-03-25T15:43:37Z</dc:date>
    <item>
      <title>Splunk Smartstore : Bucket status</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Smartstore-Bucket-status/m-p/545271#M90921</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have&amp;nbsp; Indexer cluster configured on AWS EC2 Instances&amp;nbsp; which is configured with Smart store. Since this is a Dev environment we want to stop the EC2 instances in non-business hours.&lt;/P&gt;&lt;P&gt;Could you please advise if the when we stop an indexer with smart store, the hot buckets are rolled to warm and uploaded to the smart store before the indexer peer stops.&lt;/P&gt;&lt;P&gt;Also, what would be the recommended way to stop the splunk service before stopping the EC2 Instance, would it be using splunk stop command or splunk offline command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 06:54:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Smartstore-Bucket-status/m-p/545271#M90921</guid>
      <dc:creator>samadmemon</dc:creator>
      <dc:date>2021-03-25T06:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Smartstore : Bucket status</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Smartstore-Bucket-status/m-p/545435#M90942</link>
      <description>&lt;P&gt;Hot buckets roll to warm when the indexer *starts*, not when it stops.&lt;/P&gt;&lt;P&gt;To upload your data to S2 before stopping, use these steps.&amp;nbsp; They're just my opinion, not based on anything official.&lt;/P&gt;&lt;P&gt;1) Put the indexers into detention.&amp;nbsp; This stops incoming data and prevents new hot buckets.&lt;/P&gt;&lt;P&gt;2) Manually roll each index.&amp;nbsp; See&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Backupindexeddata#Rolling_buckets_manually_from_hot_to_warm" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Backupindexeddata#Rolling_buckets_manually_from_hot_to_warm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;3) Wait for the buckets to upload.&lt;/P&gt;&lt;P&gt;4) Stop the indexers using &lt;FONT face="courier new,courier"&gt;splunk stop&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 15:43:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Smartstore-Bucket-status/m-p/545435#M90942</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-25T15:43:37Z</dc:date>
    </item>
  </channel>
</rss>

