Getting Data In

Can I thaw a bucket that has not been named properly at freeze time?

bmw_katemcd
Engager

We have some archived frozen buckets that are named "indexname-yyyy-mm-dd-hh-min" instead of the db_endtime_starttime_guid format. When we try to do the rebuild on these we get an error "fsck - Constraints given leave no buckets to operate on". Is this due to the odd naming of the buckets? They were archived using the ColdToFrozen.py script supplied with splunk but altered by one of our admins to write the buckets out with the new naming convention.

Is our data unthawable? Is there a command we can run to extract the correct information so we can rename the directory appropriately?

Labels (1)
0 Karma
1 Solution

bmw_katemcd
Engager

Answering my own question. If you open up the journal file in the bucket that's misnamed, you can extract the start and end times and use those to rename the directory to a scheme Splunk understands (db_endtime_starttime_sequence_guid). It didn't care what i used as a sequence number and the guid was grabbed from a correctly named bucket directory on one of my indexes. The process is ugly and slow but it works.

View solution in original post

0 Karma

bmw_katemcd
Engager

Answering my own question. If you open up the journal file in the bucket that's misnamed, you can extract the start and end times and use those to rename the directory to a scheme Splunk understands (db_endtime_starttime_sequence_guid). It didn't care what i used as a sequence number and the guid was grabbed from a correctly named bucket directory on one of my indexes. The process is ugly and slow but it works.

0 Karma
Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...