Getting Data In

Can I thaw a bucket that has not been named properly at freeze time?

bmw_katemcd
Engager

We have some archived frozen buckets that are named "indexname-yyyy-mm-dd-hh-min" instead of the db_endtime_starttime_guid format. When we try to do the rebuild on these we get an error "fsck - Constraints given leave no buckets to operate on". Is this due to the odd naming of the buckets? They were archived using the ColdToFrozen.py script supplied with splunk but altered by one of our admins to write the buckets out with the new naming convention.

Is our data unthawable? Is there a command we can run to extract the correct information so we can rename the directory appropriately?

Labels (1)
0 Karma
1 Solution

bmw_katemcd
Engager

Answering my own question. If you open up the journal file in the bucket that's misnamed, you can extract the start and end times and use those to rename the directory to a scheme Splunk understands (db_endtime_starttime_sequence_guid). It didn't care what i used as a sequence number and the guid was grabbed from a correctly named bucket directory on one of my indexes. The process is ugly and slow but it works.

View solution in original post

0 Karma

bmw_katemcd
Engager

Answering my own question. If you open up the journal file in the bucket that's misnamed, you can extract the start and end times and use those to rename the directory to a scheme Splunk understands (db_endtime_starttime_sequence_guid). It didn't care what i used as a sequence number and the guid was grabbed from a correctly named bucket directory on one of my indexes. The process is ugly and slow but it works.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...