Getting Data In

All sourcetypes not getting thawed

snigdhasaxena
Communicator

I had to thaw data from index abc from 1 Dec 2019-30 Dec 2019

Steps performed:

1.  Copied buckets into thaweddb folder

2. splunk rebuild bucket_name

3. Rolling restart indexer cluster

I reviewed the data in index=abc and noticed only 1 sourcetype events got thawed.

However, there are 4 more sourcetype listed in SourceType.data file bucket after rebuilding it.

Any suggestions why not all sourcetypes data got thawed ?

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...