<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: snapshot search index in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210330#M187829</link>
    <description>&lt;P&gt;You should be more specific in your question - a general question gets a general answer, a detailed question gets a detailed answer.&lt;/P&gt;

&lt;P&gt;If you snapshot the indexer and let forwarders send data afterwards, that snapshot will not contain this new data. Restoring to the snapshot will restore the state at the time of snapshot, dropping all new data.&lt;/P&gt;</description>
    <pubDate>Mon, 02 Nov 2015 18:05:54 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2015-11-02T18:05:54Z</dc:date>
    <item>
      <title>snapshot search index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210324#M187823</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I have a server that works to search-haed and a by search-index . They're virtual machines and before upgrade to search-index I wanted to rate a snap to image. if I comeback with the server by image how indexes behave ?&lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 16:33:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210324#M187823</guid>
      <dc:creator>PIETRO_CENTANNI</dc:creator>
      <dc:date>2015-10-30T16:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: snapshot search index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210325#M187824</link>
      <description>&lt;P&gt;Please restate with many more words and sample data with desired sample output.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 17:30:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210325#M187824</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-30T17:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: snapshot search index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210326#M187825</link>
      <description>&lt;P&gt;Assuming your snapshot restores the machine to the correct state, the indexes will be fine. To be on the safe side you may want to stop the indexer when making the snapshot, then you won't accidentally snapshot some in-flight data in a bad state. However, even if that happens, the damage would always be contained to that bucket.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2015 00:29:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210326#M187825</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-11-01T00:29:10Z</dc:date>
    </item>
    <item>
      <title>Re: snapshot search index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210327#M187826</link>
      <description>&lt;P&gt;Today I try to test and I tell you the result.&lt;BR /&gt;
thanks&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2015 08:29:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210327#M187826</guid>
      <dc:creator>PIETRO_CENTANNI</dc:creator>
      <dc:date>2015-11-02T08:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: snapshot search index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210328#M187827</link>
      <description>&lt;P&gt;I am sorry but this test is impossible Because there is the risk of losing dates .&lt;BR /&gt;
I stop indexer before i make the snapshot , I make the upgrade and after I start by indexer .&lt;BR /&gt;
If I turn back because there are problems and I copy the my snapshot I lose all the datas in the range time.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2015 10:01:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210328#M187827</guid>
      <dc:creator>PIETRO_CENTANNI</dc:creator>
      <dc:date>2015-11-02T10:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: snapshot search index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210329#M187828</link>
      <description>&lt;P&gt;I was thinking if I can disable forwarding setting inputs.conf in and after I make to the snapshot , make the ugrade , I do various tests without the risk arrive That datas .&lt;/P&gt;

&lt;P&gt;[splunktcp://9997]&lt;BR /&gt;
connection_host = ip&lt;BR /&gt;
disable = 1&lt;/P&gt;

&lt;P&gt;At the End of the test I can REMOVE the disable and receive all date.&lt;BR /&gt;
this is possible? this is a correct procedures?&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2015 11:41:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210329#M187828</guid>
      <dc:creator>PIETRO_CENTANNI</dc:creator>
      <dc:date>2015-11-02T11:41:20Z</dc:date>
    </item>
    <item>
      <title>Re: snapshot search index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210330#M187829</link>
      <description>&lt;P&gt;You should be more specific in your question - a general question gets a general answer, a detailed question gets a detailed answer.&lt;/P&gt;

&lt;P&gt;If you snapshot the indexer and let forwarders send data afterwards, that snapshot will not contain this new data. Restoring to the snapshot will restore the state at the time of snapshot, dropping all new data.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2015 18:05:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210330#M187829</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-11-02T18:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: snapshot search index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210331#M187830</link>
      <description>&lt;P&gt;That would indeed stop forwarders from sending data. Assuming you're able to keep all monitored files around, and can queue all other data such as network sources then yeah, this might work. &lt;/P&gt;

&lt;P&gt;As an alternative, in case of problems after the upgrade you could back up new buckets, restore the snapshot, and add in the new buckets from after the upgrade.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2015 18:07:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210331#M187830</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-11-02T18:07:40Z</dc:date>
    </item>
    <item>
      <title>Re: snapshot search index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210332#M187831</link>
      <description>&lt;P&gt;Thanks Martin for your answers&lt;/P&gt;

&lt;P&gt;Yesterday I analyzed the problem. The sending dates is via forwarder and syslog come from port 514. From like you said you monitor all is complicated.&lt;/P&gt;

&lt;P&gt;Interesting your suggestion about back up new buckets. I tried to stop indexer for 10 minutes and I see the behavior of the buckets. The folders hot_v1_nnn change in db_nnn and generate new hot_v1_xxx.&lt;BR /&gt;
But is it then simply add this folder in directory relevant?&lt;BR /&gt;
Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:45:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210332#M187831</guid>
      <dc:creator>PIETRO_CENTANNI</dc:creator>
      <dc:date>2020-09-29T07:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: snapshot search index</title>
      <link>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210333#M187832</link>
      <description>&lt;P&gt;&lt;A href="http://www.georgestarcher.com/splunk-success-with-syslog/"&gt;http://www.georgestarcher.com/splunk-success-with-syslog/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;When manually copying buckets around you need to be careful to align the bucket IDs to avoid duplicates, so make sure you do that on a testing instance first or get someone who already has done that before.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2015 12:19:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/snapshot-search-index/m-p/210333#M187832</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2015-11-03T12:19:07Z</dc:date>
    </item>
  </channel>
</rss>

