- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi,
I am looking for a documentation which describes the necessary steps in case of a disaster recovery (the host where Splunk Enterprise is installed crashes at some point) when I have only one Splunk Enterprise and receiving from some forwarders.
Let's suppose all indexed data backups have been done regularly (under $SPLUNK_HOME/var/lib/splunk/<my_index>
/db).
What is the ocfficial procedure of restoring Splunk? I found helpful this page: http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Backupindexeddata
Thanks a lot,
Skender
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi Skender,
Here are some topics you can refer to on Splunk Docs:
- Restore archived index data : http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Restorearchiveddata
- Back up KV store: http://docs.splunk.com/Documentation/Splunk/latest/Admin/BackupKVstore
- Back up configuration information: http://docs.splunk.com/Documentation/Splunk/6.5.0/Admin/Backupconfigurations
Hope it helps. Thanks!
Hunter
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Skender, it really depends how far you are willing to invest in the architecture.
The following speaks to that - Scale your deployment with Splunk Enterprise components
The most challenging aspect of the installation is obviously the indexed part. The next page at Use clusters for high availability and ease of management
explains -
-- Splunk Enterprise clusters feature automatic failover from one indexer to the next. This means that, if one or more indexers fail, incoming data continues to get indexed and indexed data continues to be searchable.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hi,
At the moment the customer has ONLY one Splunk Enterprise (no clusters), so I think I should follow the steps and suggestions for backup and restoring all buckets.
Thanks a lot,
Skender
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


Hi Skender,
Here are some topics you can refer to on Splunk Docs:
- Restore archived index data : http://docs.splunk.com/Documentation/Splunk/6.5.0/Indexer/Restorearchiveddata
- Back up KV store: http://docs.splunk.com/Documentation/Splunk/latest/Admin/BackupKVstore
- Back up configuration information: http://docs.splunk.com/Documentation/Splunk/6.5.0/Admin/Backupconfigurations
Hope it helps. Thanks!
Hunter
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Thanks a lot!
I just knew well how to bring "online" the frozen buckets, but I was not so clear about hot and warm buckets.
Skender
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


You are welcome, Skender! Glad to be of any help. 🙂
