Hi All,
I am using splunk enterprise version 7.1. I am looking for a way to backup the splunk index data into Amazon S3 bucket.
can someone suggest a way to achieve this.
I assume using hunk is deemed legacy in 7.x versions.
Thanks
Splunk Hadoop Data Roll can backup your indexes into HDFS or S3 (we recommend that you use S3A and not S3).
Here are few links that can help:
https://docs.splunk.com/Documentation/Splunk/latest/Indexer/ArchivingindexestoHadoop
https://docs.splunk.com/Documentation/Splunk/7.2.1/Indexer/ArchivingSplunkindexestoS3
https://answers.splunk.com/search.html?f=&redirect=search%2Fsearch&sort=relevance&q=s3a&type=questio...
https://www.splunk.com/blog/2015/02/11/faster-and-limitless-hunk-archiving-to-s3-with-hadoop-2-6-0.h...