<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log restoration process in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Log-restoration-process/m-p/531588#M9507</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm not sure if this is what you're asking about, but there's a doc on restoring based on internal audit logs:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/ES/6.4.0/Install/InstallEnterpriseSecuritySHC#Restore_incident_review_history_from_internal_audit_logs" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/6.4.0/Install/InstallEnterpriseSecuritySHC#Restore_incident_review_history_from_internal_audit_logs&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Dec 2020 20:09:28 GMT</pubDate>
    <dc:creator>lkutch_splunk</dc:creator>
    <dc:date>2020-12-01T20:09:28Z</dc:date>
    <item>
      <title>Log restoration process</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Log-restoration-process/m-p/531137#M9495</link>
      <description>&lt;P&gt;Hello everyone, I am facing some issues with log restoration process from azure cloud to splunk . I have gone through the &lt;STRONG&gt;epoch time conversio&lt;/STRONG&gt;n process to get the exact date for file. then restore the particular file using the shell commands.&lt;/P&gt;&lt;P&gt;But right now I want to restore&lt;STRONG&gt; two months of log data in splunk&lt;/STRONG&gt;. so the previous process is really time taking and there is a chance that we might miss some of the data for a particular time interval.&lt;/P&gt;&lt;P&gt;So is there any way we can restore the two months of date using some prebuild commands or is there any process to ease the task.&lt;/P&gt;&lt;P&gt;Thanks in advance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 11:36:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Log-restoration-process/m-p/531137#M9495</guid>
      <dc:creator>Rbsplunk95</dc:creator>
      <dc:date>2020-11-27T11:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Log restoration process</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Log-restoration-process/m-p/531588#M9507</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm not sure if this is what you're asking about, but there's a doc on restoring based on internal audit logs:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/ES/6.4.0/Install/InstallEnterpriseSecuritySHC#Restore_incident_review_history_from_internal_audit_logs" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/6.4.0/Install/InstallEnterpriseSecuritySHC#Restore_incident_review_history_from_internal_audit_logs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 20:09:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Log-restoration-process/m-p/531588#M9507</guid>
      <dc:creator>lkutch_splunk</dc:creator>
      <dc:date>2020-12-01T20:09:28Z</dc:date>
    </item>
  </channel>
</rss>

