<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Old data cannot load in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580217#M202167</link>
    <description>&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76301" target="_blank"&gt;https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76301&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if this does not help open case with support.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jan 2022 07:19:06 GMT</pubDate>
    <dc:creator>SinghK</dc:creator>
    <dc:date>2022-01-07T07:19:06Z</dc:date>
    <item>
      <title>Old data cannot load</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580203#M202162</link>
      <description>&lt;P&gt;Splunk can not load old data only load current data. Though it shows event count. Before that I have moved some splunk cold db folder&amp;nbsp; in several times to free up space . and it worked fine. I dont understand what happend now. Is there any way to recover data without splunk search? Installed in windows.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 05:43:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580203#M202162</guid>
      <dc:creator>Eshmin</dc:creator>
      <dc:date>2022-01-07T05:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Old data cannot load</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580214#M202164</link>
      <description>&lt;P&gt;Anyone there help me to recover data? I am willing to pay.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 06:51:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580214#M202164</guid>
      <dc:creator>Eshmin</dc:creator>
      <dc:date>2022-01-07T06:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: Old data cannot load</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580215#M202165</link>
      <description>&lt;P&gt;Did you manually move tsidx files??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 06:57:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580215#M202165</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-07T06:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: Old data cannot load</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580216#M202166</link>
      <description>&lt;P&gt;I have move folder from cold db. like the folders which was generated September month. and yes its contain tsidx file.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 07:03:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580216#M202166</guid>
      <dc:creator>Eshmin</dc:creator>
      <dc:date>2022-01-07T07:03:28Z</dc:date>
    </item>
    <item>
      <title>Re: Old data cannot load</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580217#M202167</link>
      <description>&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76301" target="_blank"&gt;https://community.splunk.com/t5/Monitoring-Splunk/Restore-archived-data/m-p/76301&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if this does not help open case with support.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 07:19:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580217#M202167</guid>
      <dc:creator>SinghK</dc:creator>
      <dc:date>2022-01-07T07:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Old data cannot load</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580221#M202168</link>
      <description>&lt;P&gt;Sorry for my little knowledge about it. Is there any way to get expert help for data recovery Live chat or whatsApp number? Actually I have urgency to recover last month specific data.&lt;/P&gt;&lt;P&gt;without search is there any way to load file in CSV format? coz it shows event count &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 07:33:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580221#M202168</guid>
      <dc:creator>Eshmin</dc:creator>
      <dc:date>2022-01-07T07:33:55Z</dc:date>
    </item>
    <item>
      <title>Re: Old data cannot load</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580265#M202184</link>
      <description>&lt;P&gt;Disclaimer: I haven't try this with myself, so you no warranty are given and you are doing this with your own risk!&lt;/P&gt;&lt;P&gt;If I understood right you are moving some cold data, not frozen data? I suppose that you have only one instance as all-in-one setup (indexer, search head at the same node). If it's this way then basically you should restore the situation by&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Stop splunk&lt;/LI&gt;&lt;LI&gt;Take backup of your DB_HOME&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Add need space for that old data under DB_HOME&lt;/LI&gt;&lt;LI&gt;Move/copy old data to it's original place&lt;/LI&gt;&lt;LI&gt;Start splunk&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Another option could be that you manage it as thawed data and restore it to thaweddb directory for that index. &amp;nbsp;Basically there shouldn't be need to rebuild that dir as you have moved those files without removing metadata from it. Anyhow You should stop your splunk instance and do actions when it's down.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you are starting it look what kind of errors you will gotten to splunkd.log. Especially if it cannot start.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 14:00:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Old-data-cannot-load/m-p/580265#M202184</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-07T14:00:28Z</dc:date>
    </item>
  </channel>
</rss>

