Deployment Architecture

How to backup all data Splunk has indexed?

areeter
Explorer

Hi everyone!

I would like to do a quick and dirty backup of all of my data Splunk has ever indexed. Am I fine to stop Splunk, then just take a copy of everything under $SPLUNK_HOME/var/lib/splunk ?

Thanks!

0 Karma

praveenbandi
Explorer

have you changed any of default path in index.conf? if not the actual db path will be,

$SPLUNK_HOME/var/lib/splunk /*

So I would say simply back-up the folder after shutdown the splunk service(preferred) .

Steps would be,

  1. run the above command suggested by @areeter something like this | rest /services/data/indexes | stats values(*expanded) as * by title
  2. make sure the path are same $SPLUNK_HOME/var/lib/splunk/.
  3. Stop the server ./splunk stop
  4. backup the path, cp index_pah new_path

Hope this will helps you.

0 Karma

areeter
Explorer

Cheers for that.

In that second link it states: For smaller amounts of data, shut down Splunk and just make a copy of your database directories before performing the upgrade... Where is that DB directory? Under $SPLUNK_HOME/var/lib/splunk ?

0 Karma

davebrooking
Contributor

The default location for indexes is $SPLUNK_HOME/var/lib/splunk, but when you create an index you have options to store the Home Path, Cold Path and Thawed Path elsewhere. Querying the index rest endpoint will give you a lot of information regarding your indexes, including their paths. Try the search command

| rest /services/data/indexes

and you should see what you need to backup.

Dave

0 Karma
Get Updates on the Splunk Community!

Easily Improve Agent Saturation with the Splunk Add-on for OpenTelemetry Collector

Agent Saturation What and Whys In application performance monitoring, saturation is defined as the total load ...

Explore the Latest Educational Offerings from Splunk [January 2025 Updates]

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...