<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk ITSI : Lost backup files on /var/itsi/backups in Splunk ITSI</title>
    <link>https://community.splunk.com/t5/Splunk-ITSI/Splunk-ITSI-Lost-backup-files-on-var-itsi-backups/m-p/565864#M2409</link>
    <description>&lt;P&gt;ITSI default backups do rotate,&amp;nbsp;&lt;/P&gt;&lt;P&gt;- in older versions the last one was overwritten&lt;/P&gt;&lt;P&gt;- since 4.3 and later, the last 7 are kept. and the&amp;nbsp;file name changed too include the date.&lt;BR /&gt;see&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/ITSI/4.3.0/ReleaseNotes/Newfeatures" target="_blank"&gt;https://docs.splunk.com/Documentation/ITSI/4.3.0/ReleaseNotes/Newfeatures&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The backups you have seems to be in the new format.&lt;/P&gt;&lt;P&gt;I do not know why the older ones are gone, is it a bug, did you clean up the folder during the reinstall ?&lt;BR /&gt;if you wiped the kvstore, it's possible that the record of the backups was lost, and the old files cleaned up ?&lt;/P&gt;</description>
    <pubDate>Fri, 03 Sep 2021 22:41:04 GMT</pubDate>
    <dc:creator>yannK</dc:creator>
    <dc:date>2021-09-03T22:41:04Z</dc:date>
    <item>
      <title>Splunk ITSI : Lost backup files on /var/itsi/backups</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Splunk-ITSI-Lost-backup-files-on-var-itsi-backups/m-p/550862#M2322</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We were using ITSI&amp;nbsp; 4.3.1. as it had some issues, we decided to uninstall &amp;amp; freshly install 4.7.2.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We took backup of current configuration using "create backup job"&amp;nbsp; on ITSI GUI. And, I verified that, we had backup jobs stored on /var/itsi/backups directory on respective search head server.&lt;/P&gt;&lt;P&gt;However, after installing 4.7.2 i can't see any backup jobs available on respective directory. it got overwritten by 4.7.2 backups as below.&lt;/P&gt;&lt;P&gt;[root@server backups]# pwd&lt;BR /&gt;/opt/splunk/var/itsi/backups&lt;BR /&gt;[root@server backups]# ls&lt;BR /&gt;ItsiDefaultScheduledBackup-1620340301.zip&lt;BR /&gt;ItsiDefaultScheduledBackup-1620343842.zip&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to retrieve full &amp;amp; partial backups which we took on earlier version (4.3.2) as we had all our services, KPI's there and we don't have any other backups taken for same ?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance for your support.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 16:42:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Splunk-ITSI-Lost-backup-files-on-var-itsi-backups/m-p/550862#M2322</guid>
      <dc:creator>Master_Blaster</dc:creator>
      <dc:date>2021-05-07T16:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ITSI : Lost backup files on /var/itsi/backups</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Splunk-ITSI-Lost-backup-files-on-var-itsi-backups/m-p/550865#M2323</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/15147"&gt;@somesoni2&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1406"&gt;@woodcock&lt;/a&gt;&amp;nbsp;Please help&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 21:17:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Splunk-ITSI-Lost-backup-files-on-var-itsi-backups/m-p/550865#M2323</guid>
      <dc:creator>Master_Blaster</dc:creator>
      <dc:date>2021-05-07T21:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ITSI : Lost backup files on /var/itsi/backups</title>
      <link>https://community.splunk.com/t5/Splunk-ITSI/Splunk-ITSI-Lost-backup-files-on-var-itsi-backups/m-p/565864#M2409</link>
      <description>&lt;P&gt;ITSI default backups do rotate,&amp;nbsp;&lt;/P&gt;&lt;P&gt;- in older versions the last one was overwritten&lt;/P&gt;&lt;P&gt;- since 4.3 and later, the last 7 are kept. and the&amp;nbsp;file name changed too include the date.&lt;BR /&gt;see&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/ITSI/4.3.0/ReleaseNotes/Newfeatures" target="_blank"&gt;https://docs.splunk.com/Documentation/ITSI/4.3.0/ReleaseNotes/Newfeatures&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The backups you have seems to be in the new format.&lt;/P&gt;&lt;P&gt;I do not know why the older ones are gone, is it a bug, did you clean up the folder during the reinstall ?&lt;BR /&gt;if you wiped the kvstore, it's possible that the record of the backups was lost, and the old files cleaned up ?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 22:41:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-ITSI/Splunk-ITSI-Lost-backup-files-on-var-itsi-backups/m-p/565864#M2409</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2021-09-03T22:41:04Z</dc:date>
    </item>
  </channel>
</rss>

