Deployment Architecture

Splunk Indexed Data Backup

sanjubaba
Path Finder

Can we take full backup of entire var directory on the Splunk indexer machine if we have enough available space?

Labels (3)
1 Solution

inventsekar
SplunkTrust
SplunkTrust

Hi @sanjubaba Yes, taking full back up of entire var directory is good, even the full /opt/splunk backup is better (the config files under /opt/splunk/etc/ will be backed up).

 

more details:

https://docs.splunk.com/Documentation/Splunk/8.0.6/Indexer/Backupindexeddata

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

View solution in original post

inventsekar
SplunkTrust
SplunkTrust

Hi @sanjubaba Yes, taking full back up of entire var directory is good, even the full /opt/splunk backup is better (the config files under /opt/splunk/etc/ will be backed up).

 

more details:

https://docs.splunk.com/Documentation/Splunk/8.0.6/Indexer/Backupindexeddata

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
Get Updates on the Splunk Community!

Good Sourcetype Naming

When it comes to getting data in, one of the earliest decisions made is what to use as a sourcetype. Often, ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Splunk App for Anomaly Detection End of Life Announcement

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...