<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk bucketinnh in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-bucketinnh/m-p/477842#M99781</link>
    <description>&lt;P&gt;Hello everyone &lt;/P&gt;

&lt;P&gt;I would like to know the steps to aches below questions can anyone please help me &lt;BR /&gt;
1. How to move data from cold bucket to hot bucket ( I have already gone through some steps in community like take the back up of cold bucket and replace the hot bucket with that something like that but I was not clear ..) &lt;/P&gt;

&lt;P&gt;Can anyone please help me with the steps &lt;BR /&gt;
2.. Second in a log I have 2 different kind of logs I want to send those to different indexes &lt;BR /&gt;
Ex : I have  a and b in the log i want to send a to index1 and b to index2 &lt;/P&gt;

&lt;P&gt;Can anyone please provide the steps to achieve above &lt;/P&gt;</description>
    <pubDate>Sun, 23 Feb 2020 16:12:37 GMT</pubDate>
    <dc:creator>itzkirankumar1</dc:creator>
    <dc:date>2020-02-23T16:12:37Z</dc:date>
    <item>
      <title>Splunk bucketinnh</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-bucketinnh/m-p/477842#M99781</link>
      <description>&lt;P&gt;Hello everyone &lt;/P&gt;

&lt;P&gt;I would like to know the steps to aches below questions can anyone please help me &lt;BR /&gt;
1. How to move data from cold bucket to hot bucket ( I have already gone through some steps in community like take the back up of cold bucket and replace the hot bucket with that something like that but I was not clear ..) &lt;/P&gt;

&lt;P&gt;Can anyone please help me with the steps &lt;BR /&gt;
2.. Second in a log I have 2 different kind of logs I want to send those to different indexes &lt;BR /&gt;
Ex : I have  a and b in the log i want to send a to index1 and b to index2 &lt;/P&gt;

&lt;P&gt;Can anyone please provide the steps to achieve above &lt;/P&gt;</description>
      <pubDate>Sun, 23 Feb 2020 16:12:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-bucketinnh/m-p/477842#M99781</guid>
      <dc:creator>itzkirankumar1</dc:creator>
      <dc:date>2020-02-23T16:12:37Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk bucketinnh</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-bucketinnh/m-p/477843#M99782</link>
      <description>&lt;P&gt;1: You cannot create hot buckets, only &lt;CODE&gt;splunkd&lt;/CODE&gt; can.&lt;BR /&gt;
2: &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Feb 2020 20:26:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-bucketinnh/m-p/477843#M99782</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-02-23T20:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk bucketinnh</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-bucketinnh/m-p/477844#M99783</link>
      <description>&lt;P&gt;Thanks for the inputs but I want to retrieve cold bucket data to hot bucket is it possible &lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 03:51:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-bucketinnh/m-p/477844#M99783</guid>
      <dc:creator>itzkirankumar1</dc:creator>
      <dc:date>2020-02-24T03:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk bucketinnh</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-bucketinnh/m-p/477845#M99784</link>
      <description>&lt;P&gt;IT IS IMPOSSIBLE and furthermore doesn't even make sense.  If you really mean &lt;CODE&gt;warm&lt;/CODE&gt; instead of &lt;CODE&gt;hot&lt;/CODE&gt; then all you need to do is move the bucket folder and restart the Cluster Master.  But even that is pretty pointless because unless you have modified &lt;CODE&gt;frozenTimePeriodInSeconds&lt;/CODE&gt; or expanded your warm disk volume, it is just going to move back to &lt;CODE&gt;cold&lt;/CODE&gt; immediately.  See my new answer.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 14:41:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-bucketinnh/m-p/477845#M99784</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-02-24T14:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk bucketinnh</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-bucketinnh/m-p/477846#M99785</link>
      <description>&lt;P&gt;Perhaps you are using the wrong terms and thus asking the wrong question because, as-written, what you are asking makes no sense at all.  Perhaps what you are meaning to ask is, &lt;CODE&gt;How do I thaw frozen data to make it searchable again&lt;/CODE&gt;.  That question makes a great deal of sense, and even has answers but nowhere in those answers is there any step to make a bucket &lt;CODE&gt;hot&lt;/CODE&gt; again.&lt;BR /&gt;
The answer to my reformulation of your question is here:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Restorearchiveddata"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Restorearchiveddata&lt;/A&gt;&lt;BR /&gt;
But keep in mind that this only will work if you have first done this (which most people have not done):&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Automatearchiving"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Automatearchiving&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Backupindexeddata"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Indexer/Backupindexeddata&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 14:56:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-bucketinnh/m-p/477846#M99785</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2020-02-24T14:56:27Z</dc:date>
    </item>
  </channel>
</rss>

