<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to view thawed data in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458424#M129444</link>
    <description>&lt;P&gt;Refer to below comment as i cannot attach pictures here in this thread.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Nov 2019 15:00:24 GMT</pubDate>
    <dc:creator>Prakash493</dc:creator>
    <dc:date>2019-11-19T15:00:24Z</dc:date>
    <item>
      <title>Unable to view thawed data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458418#M129438</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I'm testing thawing of some frozen data and it's not working. I have thawed some previously frozen data and am expecting to see it in the search, but the search result returned is empty. &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Some questions:&lt;/STRONG&gt;&lt;BR /&gt;
- Could this a bug (I'm following the recommended method from Splunk admin training)? &lt;BR /&gt;
- How could I take my investigation further?&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Procedure&lt;/STRONG&gt;:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;stop Splunk&lt;/LI&gt;
&lt;LI&gt;copy frozen data (bucket) to a thawed directory&lt;/LI&gt;
&lt;LI&gt;run rebuild command - Splunk rebuilds (this appears to work as I see the metadata files are created (Sources.data, bloomfilter, Hosts.data etc).&lt;/LI&gt;
&lt;LI&gt;start Splunk&lt;/LI&gt;
&lt;LI&gt;search (index=itops earliest = -365d). Result: 0 events - No results found. Try expanding the time range.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;&lt;STRONG&gt;A few more details:&lt;/STRONG&gt;&lt;BR /&gt;
- Running SE version 7.3&lt;BR /&gt;
- the data is from 2 weeks ago (I set the data in the index to age out/freeze after two days)&lt;BR /&gt;
- this is a test platform&lt;BR /&gt;
- Seeing some weird logs in the internal index that I don't understand:  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; 7/9/19 5:14:53.226 PM   07-09-2019 17:14:53.226 +0200 INFO  DatabaseDirectoryManager - Getting size on disk: Unable to get size on disk for bucket id=itops~5~8D8C5421-3FB9-4E28-A7DA-D62472398A71 path="C:\Program Files\Splunk\var\lib\splunk\itops\thaweddb\db_1561999955_1558706749_5" (This is usually harmless as we may be racing with a rename in BucketMover or the S2SFileReceiver thread, which should be obvious in log file; the previous WARN message about this path can safely be ignored.) caller=getBucketManifestValues

host = XXXXXX
source = C:\Program Files\Splunk\var\log\splunk\splunkd.log
sourcetype = splunkd
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 09 Jul 2019 15:38:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458418#M129438</guid>
      <dc:creator>BARNEYRUDD</dc:creator>
      <dc:date>2019-07-09T15:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view thawed data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458419#M129439</link>
      <description>&lt;P&gt;any update on this? have any luck figuring it out?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 02:41:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458419#M129439</guid>
      <dc:creator>lhanich1</dc:creator>
      <dc:date>2019-11-15T02:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view thawed data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458420#M129440</link>
      <description>&lt;P&gt;Hi @lhanich1, no updates, I haven't looked any further into this.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 09:39:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458420#M129440</guid>
      <dc:creator>BARNEYRUDD</dc:creator>
      <dc:date>2019-11-15T09:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view thawed data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458421#M129441</link>
      <description>&lt;P&gt;i been running into same issue that you are in splunk 7.0.2 their was a bug it prevents the data to be searchable i ended up with setting up a standalone indexer thaw the data their , rebuild the bucket and integrate with search head cluster then my data was searchable.&lt;/P&gt;

&lt;P&gt;Tip: You check that by using splunk rest api to go to that particular index and if you see the frozen flag set to true means your rebuilding of buckets is not working.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 22:23:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458421#M129441</guid>
      <dc:creator>Prakash493</dc:creator>
      <dc:date>2019-11-18T22:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view thawed data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458422#M129442</link>
      <description>&lt;P&gt;Thanks @Prakash493. Could you give me the exact name of the frozen flag you are referencing? And the method to check for it if my REST URL is wrong?&lt;/P&gt;

&lt;P&gt;I looked at my problem again and realised I was getting a warning on the rebuild command, not sure if it's important/significant or not. I'm using a windows laptop with restricted admin privileges, so maybe my issue is to do with that.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;WARN  Fsck - Failed to rename tmpDir='C:\Program Files\Splunk\var\lib\splunk\ito
ps\db\db_1561999955_1558706749_5-tmp' to stageDir='C:\Program Files\Splunk\var\l
ib\splunk\&amp;lt;myindex&amp;gt;\thaweddb\db_1561999955_1558706749_5-stage'.Reason='ERROR_ACCESS_
DENIED'. Will try to copy contents
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So I tried the thaw on a Linux VM running Splunk and my data thawed correctly and was searchable.&lt;/P&gt;

&lt;P&gt;I then interrogated the rest endpoints on the Windows and Linux machine, but I didn't find the "frozen" flag you were talking about. I found references to thaw and frozen but nothing surprising. For example fields that reference frozen for the index in question:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;coldToFrozenDir - C:\xxxxxxxxx\frozen_directory
coldToFrozenScript - No value
frozenTimePeriodInSecs - 172800
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;REST API URL I used:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="https://127.0.0.1:8089/servicesNS/nobody/search/data/indexes/&amp;lt;my" target="test_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/search/data/indexes/&amp;lt;my&lt;/A&gt; _index&amp;gt;____      .
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 19 Nov 2019 14:35:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458422#M129442</guid>
      <dc:creator>BARNEYRUDD</dc:creator>
      <dc:date>2019-11-19T14:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view thawed data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458423#M129443</link>
      <description>&lt;P&gt;Here you go the Rest APi URL of cluster master : &lt;A href="https://clustermasteruri:8089/services/cluster/master/buckets/%7E"&gt;https://clustermasteruri:8089/services/cluster/master/buckets/~&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Here is a ref screenshot , if you see the frozen flag=1 and bucket state is saying searchable means the bucket is not searchable due to this bug where its saying frozen = 1 and if that saying frozen flag 0 and bucket state is searchable means u r good to go ;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/7288i0D85BE8DB05CA816/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 14:59:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458423#M129443</guid>
      <dc:creator>Prakash493</dc:creator>
      <dc:date>2019-11-19T14:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view thawed data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458424#M129444</link>
      <description>&lt;P&gt;Refer to below comment as i cannot attach pictures here in this thread.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 15:00:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458424#M129444</guid>
      <dc:creator>Prakash493</dc:creator>
      <dc:date>2019-11-19T15:00:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view thawed data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458425#M129445</link>
      <description>&lt;P&gt;if your problem is solved please accept the answer to help future peoples.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 21:29:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458425#M129445</guid>
      <dc:creator>Prakash493</dc:creator>
      <dc:date>2019-11-21T21:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view thawed data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458426#M129446</link>
      <description>&lt;P&gt;Hi @Prakash493 I tried the REST URL you suggested but got nothing (empty page with no results) and I think it's because my Splunk deployment where I have the problem is not in a cluster, it's standalone. I tried modifying the URL to find an equivalent for a standalone environment but couldn't find anything. Do you know what the equivalent URL for a standalone environment would be? I'm thinking maybe your problem is specific only to a clustered environment.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 08:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/458426#M129446</guid>
      <dc:creator>BARNEYRUDD</dc:creator>
      <dc:date>2019-11-22T08:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view thawed data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/503994#M140704</link>
      <description>&lt;P&gt;Hello, same issue with 7.1.4, should it be fixed? Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 20:13:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/503994#M140704</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2020-06-11T20:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view thawed data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/503999#M140708</link>
      <description>&lt;P&gt;Restarted the Cluster master and it works now!&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2020 20:54:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/503999#M140708</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2020-06-11T20:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view thawed data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/546344#M154872</link>
      <description>&lt;P&gt;I confirm I had the same issue (using Splunk 8.0.5), after a restore thawed buckets were not searchable.&lt;/P&gt;&lt;P&gt;Checking with the REST API call the flag frozen was equal to 1.&lt;/P&gt;&lt;P&gt;I solved restarting the Master Node, even if the&amp;nbsp;REST API call still&amp;nbsp; give the frozen flag equal to 1 (but lot more information are showed after the restart), the thawed buckets are now searchable.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 09:00:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/546344#M154872</guid>
      <dc:creator>edoardo_vicendo</dc:creator>
      <dc:date>2021-04-01T09:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to view thawed data</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/686180#M234115</link>
      <description>&lt;P&gt;In clustered Splunk folder names in thaweddb folder should match &lt;EM&gt;db_&lt;/EM&gt;&amp;lt;&lt;EM&gt;newest_time&lt;/EM&gt;&amp;gt;&lt;EM&gt;&amp;lt;oldest_time&amp;gt;_&lt;/EM&gt;&amp;lt;&lt;EM&gt;bucketid&lt;/EM&gt;&amp;gt;_&amp;lt;&lt;EM&gt;guid&amp;gt; &lt;/EM&gt;naming convention. Also you can restore data from another indexer, just change the GUID to local (find in etc/instance.cfg). Please note that rb_ prefix should also be renamed to db_&lt;/P&gt;</description>
      <pubDate>Thu, 02 May 2024 14:25:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unable-to-view-thawed-data/m-p/686180#M234115</guid>
      <dc:creator>ilgiz</dc:creator>
      <dc:date>2024-05-02T14:25:03Z</dc:date>
    </item>
  </channel>
</rss>

