<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restore archived data in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76302#M7238</link>
    <description>&lt;P&gt;you need to give more details on what you did...in the meanwhile a good explanation here &lt;A href="http://blogs.splunk.com/2012/02/21/restoring-an-index/"&gt; index restoration&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Feb 2012 16:13:01 GMT</pubDate>
    <dc:creator>MarioM</dc:creator>
    <dc:date>2012-02-22T16:13:01Z</dc:date>
    <item>
      <title>Restore archived data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76301#M7237</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;I could not able to Restore archived data and could not able to make it searchable even after following 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Restore archived data instractions in Splunk Admin Manual. Can any one please help on this.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2012 13:43:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76301#M7237</guid>
      <dc:creator>ssingh5</dc:creator>
      <dc:date>2012-02-22T13:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: Restore archived data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76302#M7238</link>
      <description>&lt;P&gt;you need to give more details on what you did...in the meanwhile a good explanation here &lt;A href="http://blogs.splunk.com/2012/02/21/restoring-an-index/"&gt; index restoration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Feb 2012 16:13:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76302#M7238</guid>
      <dc:creator>MarioM</dc:creator>
      <dc:date>2012-02-22T16:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Restore archived data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76303#M7239</link>
      <description>&lt;P&gt;I have archived logs of one of my index named OS the index structure is as followed. I have followed the following steps to restore archived logs back to the Thaweddb bucket in os index but still icould not able to search those logs in that time fram. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Index:&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;[os] &lt;BR /&gt;
homePath = $SPLUNK_DB/os/db &lt;BR /&gt;
coldPath = $SPLUNK_DB/os/colddb &lt;BR /&gt;
thawedPath = $SPLUNK_DB/os/thaweddb&lt;/P&gt;

&lt;P&gt;Recovery Steps followed:&lt;/P&gt;

&lt;P&gt;Copy your archive bucket to a temporary location in the thawed directory: &lt;BR /&gt;
cp -r db_1181756465_1162600547_0 $SPLUNK_HOME/var/lib/splunk/os/thaweddb/temp_db_1181756465_1162600547_0&lt;/P&gt;

&lt;P&gt;Execute the rebuild command on the temporary bucket to rebuild the Splunk indexes and associated files: &lt;BR /&gt;
splunk rebuild $SPLUNK_HOME/var/lib/splunk/os/thaweddb/temp_db_1181756465_1162600547_0&lt;/P&gt;

&lt;P&gt;Rename the temporary bucket to something that Splunk will recognize: &lt;BR /&gt;
cd $SPLUNK_HOME/var/lib/splunk/os/thaweddb/mv temp_db_1181756465_1162600547_0 db_1181756465_1162600547_1001&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 11:26:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76303#M7239</guid>
      <dc:creator>ssingh5</dc:creator>
      <dc:date>2020-09-28T11:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Restore archived data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76304#M7240</link>
      <description>&lt;P&gt;I tried this method many times, but can not search event Jan2011 -July 2011.&lt;BR /&gt;
(the strange was it can search 2010 data) What's wrong ?&lt;BR /&gt;
my index.conf was set as&lt;/P&gt;

&lt;P&gt;[juniper]&lt;BR /&gt;
coldToFrozenScript = /opt/splunk/bin/compressedExport.sh&lt;BR /&gt;
homePath = /data/splunk/juniper/db&lt;BR /&gt;
coldPath = /data/splunk/juniper/colddb&lt;BR /&gt;
thawedPath = /data/splunk/juniper/thaweddb&lt;BR /&gt;
frozenTimePeriodInSecs = 31536000&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2012 10:19:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76304#M7240</guid>
      <dc:creator>nutjy</dc:creator>
      <dc:date>2012-02-24T10:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: Restore archived data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76305#M7241</link>
      <description>&lt;P&gt;This did not work for us!!!!&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2014 17:54:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76305#M7241</guid>
      <dc:creator>laurie_maginn</dc:creator>
      <dc:date>2014-03-04T17:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: Restore archived data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76306#M7242</link>
      <description>&lt;P&gt;Try this script and that should work fine &lt;A href="https://github.com/tuwid/splunk_frozen_db_restore"&gt;https://github.com/tuwid/splunk_frozen_db_restore&lt;/A&gt;&lt;BR /&gt;
as follows: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;root@XXXXXX:~# python splunk_frozen_db_restore.py
We're using the default index path, for custom indexes please adjust the path variable here
Enter index:winevents_security
Enter start date: (eg 30.12.2015): 31.12.2015
Enter end date: (eg 30.12.2015): 01.01.2016
[+] Searching dates on index winevents_security
in /opt/splunk/var/lib/splunk/winevents_security/frozendb/
1451516400
1451602800
Got 313 elements from /opt/splunk/var/lib/splunk/winevents_security/frozendb/
Found : db_1452350660_1451453107_329
[+] Copying databases into thaweddb..
cp -R /opt/splunk/var/lib/splunk/winevents_security/frozendb/db_1452350660_1451453107_329 /opt/splunk/var/lib/splunk/winevents_security/thaweddb/
[+] Rebuilding DBs
splunkd fsck repair --one-bucket --include-hots --bucket-path=/opt/splunk/var/lib/splunk/winevents_security/thaweddb/db_1452350660_1451453107_329 --log-to--splunkd-log
root@XXXXXX:~#
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 21 Apr 2016 14:02:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76306#M7242</guid>
      <dc:creator>arber</dc:creator>
      <dc:date>2016-04-21T14:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: Restore archived data</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76307#M7243</link>
      <description>&lt;P&gt;&lt;A href="https://www.conducivesi.com/splunk-archiver-video/"&gt;https://www.conducivesi.com/splunk-archiver-video/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 18:50:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76307#M7243</guid>
      <dc:creator>austincisneros</dc:creator>
      <dc:date>2019-02-04T18:50:42Z</dc:date>
    </item>
  </channel>
</rss>

