Archive
Highlighted

Restore logs to Splunk

Hi Team,

Please look into this case on priority :
In Splunk environment(3 Indexer,3 search head,1 deployment server) we have lost data for one application which is older than 3 months due to space issue and that was not archived anywhere.
When checked with backup team, they have the backup tapes which has entire backup data from all 3 indexers.

Please help or provide inputs on below points :
1. Would it be possible to restore the data again to Splunk
2. Is there any risk involved/any other way the purged data can make it searchable again in Splunk

Tags (1)
0 Karma