<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I restore data from a crashed installation in Installation</title>
    <link>https://community.splunk.com/t5/Installation/How-can-I-restore-data-from-a-crashed-installation/m-p/65439#M9331</link>
    <description>&lt;P&gt;If all the data is there and intact, you should be able to &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Reinstall Splunk&lt;/LI&gt;
&lt;LI&gt;Restore the Splunk etc directory from a recent backup&lt;/LI&gt;
&lt;LI&gt;Start Splunk&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In addition to making sure that your indexed info is all there, this will also restore your licenses, your users' saved searches, etc. etc.&lt;/P&gt;

&lt;P&gt;This is not the only way to get service restored, but it is the easiest way that I know. If you can't restore the Splunk etc directory, then you will need to reconstruct the configuration files; this would be a PITA. The data is described in indexes.conf - but that is only part of what you really need.&lt;/P&gt;

&lt;P&gt;It's great that your data partition survived intact.&lt;/P&gt;

&lt;P&gt;Post back if you need more help.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Jun 2012 13:07:43 GMT</pubDate>
    <dc:creator>lguinn2</dc:creator>
    <dc:date>2012-06-01T13:07:43Z</dc:date>
    <item>
      <title>How can I restore data from a crashed installation</title>
      <link>https://community.splunk.com/t5/Installation/How-can-I-restore-data-from-a-crashed-installation/m-p/65438#M9330</link>
      <description>&lt;P&gt;Our splunk server has 2 windows partitions, one for the OS and Splunk, the other for the splunk data.&lt;/P&gt;

&lt;P&gt;For reasons I shall not go into it has been necessary to trash the OS partition and rebuild it from scratch.&lt;/P&gt;

&lt;P&gt;I still have the splunk data on the data partition (and a tape backup).  The server was shutdown cleanly prior to the OS partition being trashed.&lt;/P&gt;

&lt;P&gt;My plan is to reinstall the OS (currently underway) and then install Splunk.  I will then need to import/restore the data some how but I am not sure how to go about this.&lt;/P&gt;

&lt;P&gt;Can anyone help?&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2012 10:21:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-can-I-restore-data-from-a-crashed-installation/m-p/65438#M9330</guid>
      <dc:creator>jezh</dc:creator>
      <dc:date>2012-06-01T10:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: How can I restore data from a crashed installation</title>
      <link>https://community.splunk.com/t5/Installation/How-can-I-restore-data-from-a-crashed-installation/m-p/65439#M9331</link>
      <description>&lt;P&gt;If all the data is there and intact, you should be able to &lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Reinstall Splunk&lt;/LI&gt;
&lt;LI&gt;Restore the Splunk etc directory from a recent backup&lt;/LI&gt;
&lt;LI&gt;Start Splunk&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;In addition to making sure that your indexed info is all there, this will also restore your licenses, your users' saved searches, etc. etc.&lt;/P&gt;

&lt;P&gt;This is not the only way to get service restored, but it is the easiest way that I know. If you can't restore the Splunk etc directory, then you will need to reconstruct the configuration files; this would be a PITA. The data is described in indexes.conf - but that is only part of what you really need.&lt;/P&gt;

&lt;P&gt;It's great that your data partition survived intact.&lt;/P&gt;

&lt;P&gt;Post back if you need more help.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jun 2012 13:07:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-can-I-restore-data-from-a-crashed-installation/m-p/65439#M9331</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-06-01T13:07:43Z</dc:date>
    </item>
  </channel>
</rss>

