Deployment Architecture

Restoration of archived logs

garima_chauhan
Path Finder

Hi,

I have been able to restore the archived bucket successfully in Splunk by following the steps mentioned in the Splunk documentation for Windows.

But, the steps state that we have to restore every bucket individually, which will become very tedious in case there are a large number of buckets to be restored, say 100 or more.Is there any way of restoring all the buckets in one go?

Please help.

0 Karma
1 Solution

jtrucks
Splunk Employee
Splunk Employee

Write a script to iterate through the buckets to move them, then at the end of the script, restart Splunk. This is generally how most of us do it.

--
Jesse Trucks
Minister of Magic

View solution in original post

jtrucks
Splunk Employee
Splunk Employee

Write a script to iterate through the buckets to move them, then at the end of the script, restart Splunk. This is generally how most of us do it.

--
Jesse Trucks
Minister of Magic

garima_chauhan
Path Finder

Thanks jtrucks, but I am relatively new to this field, it would be really helpful if you could share the script.

0 Karma

somesoni2
Revered Legend

You may use any script (VBScript/Python) which may allow to your use loops to move all the archived bucket into thaweddb with proper name and then restart the splunk at once.

0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

Industry Solutions for Supply Chain and OT, Amazon Use Cases, Plus More New Articles ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...